Vulnerabilities (CVE)

Filtered by vendor Fluentforms Subscribe
Filtered by product Contact Form
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-34620 1 Fluentforms 1 Contact Form 2021-07-10 6.8 MEDIUM 8.8 HIGH
The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions