CVE · Medium

CVE-2024-9651 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-9651 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.2.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.2.1 5.2.1 2024-11-18

CVE-2024-9651

The Fluent Forms plugin, versions up to 5.2.0, is susceptible to Stored Cross-Site Scripting when used in WordPress, particularly in multi-site setups without unfiltered_html enabled. Admin users with sufficient privileges can inject malicious scripts that will run whenever other users view the affected pages.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.