CVE-2021-34620: CSRF in WP Fluent Forms < 3.6.67 allows stored XSS and Privilege Escalation
The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34620?
CVE-2021-34620 is a vulnerability in the WP Fluent Forms plugin < 3.6.67 for WordPress that allows for Cross-Site Request Forgery, leading to stored Cross-Site Scripting and limited Privilege Escalation.
How severe is CVE-2021-34620?
CVE-2021-34620 has a severity rating of 8.8 (high).
What software is affected by CVE-2021-34620?
The WP Fluent Forms plugin < 3.6.67 for WordPress is affected by CVE-2021-34620.
Is there a fix for CVE-2021-34620?
Yes, make sure to update the WP Fluent Forms plugin to a version greater than or equal to 3.6.67 to fix CVE-2021-34620.
Where can I find more information about CVE-2021-34620?
You can find more information about CVE-2021-34620 on the official WordPress plugin page and the Wordfence blog.