Input validation vulnerability in Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder 5.1.19

The plugin called Contact Form by Fluent Forms, which is used to create quizzes, surveys, and drag and drop forms on WordPress, has a security vulnerability. This vulnerability is called Stored Cross-Site Scripting and it affects all versions of the plugin up to 5.1.19. This happens because the plugin does not properly filter and protect information entered in the ‘description’ and ‘btn_txt’ fields. This allows malicious users with certain permissions and roles to insert harmful code into pages, which will then run whenever someone visits those pages.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.