CVE-2024-9651: Contact Form Plugin by Fluent Forms < 5.2.1 - Admin+ Stored XSS
The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9651?
CVE-2024-9651 has a high severity due to the risk of Stored Cross-Site Scripting attacks affecting high privilege users.
How do I fix CVE-2024-9651?
To fix CVE-2024-9651, update the Fluent Forms WordPress plugin to version 5.2.1 or later.
Who is affected by CVE-2024-9651?
CVE-2024-9651 affects users of the Fluent Forms WordPress plugin prior to version 5.2.1, especially those with administrative privileges.
What type of vulnerability is CVE-2024-9651?
CVE-2024-9651 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
Can CVE-2024-9651 be exploited on multisite installations?
Yes, CVE-2024-9651 can be exploited on multisite installations where the unfiltered_html capability is disabled.