Extension WordPress

Vulnérabilités Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder, page 2

Cette page rassemble les failles publiées pour Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

34Vulnérabilités
1Critiques
34Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

34 fiches

CVE-2024-6521 Moyenne · 4,4
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dropdown fields in all versions up to, and including, 5.1.19 due…

Versions affectées

*-5.1.19

Correctif

5.1.20

Publication

27/07/2024

CVE-2024-6703 Moyenne · 4,9
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 – Authenticated (Subscriber+) Stored Cross-Site Scripting via Welcome Screen Fields

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ and 'btn_txt' parameters in all versions up to, and…

Versions affectées

*-5.1.19

Correctif

5.1.20

Publication

26/07/2024

CVE-2024-4157 Élevée · 7,5
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 – PHP Object Injection via extractDynamicValues

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted…

Versions affectées

*-5.1.15

Correctif

5.1.16

Publication

21/05/2024

CVE-2024-2772 Moyenne · 6,4
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.13 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 5.1.13 due…

Versions affectées

*-5.1.13

Correctif

5.1.14

Publication

17/05/2024

CVE-2024-2782 Élevée · 7,5
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 – Missing Authorization to Setting Manipulation

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API…

Versions affectées

*-5.1.16

Correctif

5.1.17

Publication

17/05/2024

CVE-2024-2771 Critique · 9,8
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 – Missing Authorization to Settings Update and Limited Privilege Escalation

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in…

Versions affectées

*-5.1.16

Correctif

5.1.17

Publication

17/05/2024

CVE-2024-4709 Moyenne · 6,4
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parameter in versions up to, and including, 5.1.16 due…

Versions affectées

*-5.1.16

Correctif

5.1.17

Publication

17/05/2024

CVE-2023-6957 Moyenne · 4,9
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Fluent Forms <= 5.1.9 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.9 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-5.1.9

Correctif

5.1.10

Publication

05/03/2024

CVE-2024-0618 Moyenne · 4,4
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Fluent Forms <= 5.1.5 – Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title

The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to…

Versions affectées

*-5.1.5

Correctif

5.1.7

Publication

18/01/2024

CVE-2023-41952 Moyenne · 5,3
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Contact Form for Plugin by Fluent Forms <= 5.0.8 – Insecure Direct Object Reference

The Contact Form for Plugin by Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.8 via the addIsRenderableFilter() function due to missing validation on the publication status of…

Versions affectées

[*, 5.0.9)

Correctif

5.0.9

Publication

08/09/2023

CVE-2023-24410 Élevée · 7,2
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

FluentForm <= 4.3.25 – Authenticated (Administrator+) SQL Injection

The FluentForm plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.3.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

Versions affectées

*-4.3.25

Correctif

5.0.0

Publication

12/07/2023

CVE-2023-0546 Moyenne · 6,4
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

FluentForms <= 4.3.24 – Authenticated(Contributor+) Stored Cross-Site Scripting

The FluentForms plugin for WrodPress is vulnerable to stored Cross-Site Scripting via custom form fields in versions up to, and including, 4.3.24. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web…

Versions affectées

*-4.3.24

Correctif

4.3.25

Publication

20/03/2023

CVE-2022-3463 Élevée · 8,3
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Contact Form Plugin by FluentForm <= 4.3.12 – CSV Injection

The Contact Form Plugin by FluentForm plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 4.3.12. This allows attackers to embed untrusted input into exported CSV files, which can result in code execution…

Versions affectées

*-4.3.12

Correctif

4.3.13

Publication

17/10/2022

CVE-2021-34620 Élevée · 8,8
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

WP Fluent Forms < 3.6.67 – Stored Cross-Site Scripting

The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX…

Versions affectées

[*, 3.6.67)

Correctif

3.6.67

Publication

16/06/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités