CVE · Medium

CVE-2023-6957 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6957 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.1.10 5.1.10 2024-03-05

CVE-2023-6957

The Fluent Forms plugin for WordPress is susceptible to stored cross-site scripting vulnerabilities in versions 5.1.9 and earlier because it fails to properly sanitize inputs and escape outputs. An attacker with the capability to create forms can inject malicious scripts that execute when other users view affected pages, with the attack surface depending on the form creation permissions an administrator assigns. By default, only administrators can create forms, but this permission can be extended to lower-privileged roles like contributors, expanding the vulnerability's reach.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.