CVE Database /
CVE-2024-30430
CVE · Medium
CVE-2024-30430 — FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 2.8.45
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-30430
|
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 2.8.45 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.9
|
< 2.8.45
|
2.8.45 |
2024-03-28 |
—
|
CVE-2024-30430
The Fluent CRM plugin for WordPress contains a cross-site scripting vulnerability that was discovered by Ananda Dhakal and reported through Patchstack. An attacker could exploit this flaw to inject malicious code into the website, allowing execution of arbitrary scripts like redirects, ads, or HTML content that would run when visitors access the site. The vulnerability affects versions prior to 2.8.45, where it has been patched and resolved.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings