First published: Wed Jul 07 2021(Updated: )
The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions
Credit: security@wordfence.com security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fluent Forms | <3.6.67 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34620 is a vulnerability in the WP Fluent Forms plugin < 3.6.67 for WordPress that allows for Cross-Site Request Forgery, leading to stored Cross-Site Scripting and limited Privilege Escalation.
CVE-2021-34620 has a severity rating of 8.8 (high).
The WP Fluent Forms plugin < 3.6.67 for WordPress is affected by CVE-2021-34620.
Yes, make sure to update the WP Fluent Forms plugin to a version greater than or equal to 3.6.67 to fix CVE-2021-34620.
You can find more information about CVE-2021-34620 on the official WordPress plugin page and the Wordfence blog.