WordPress Fluent Forms是WordPress基金会开源的一款表单插件。 WordPress Fluent Forms 6.2.11及之前版本存在跨站脚本漏洞,该漏洞源于输入清理和输出转义不足,可能导致未认证攻击者注入任意Web脚本,当管理员在WordPress管理后台查看表单的提交日志时在浏览器中执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpmanageninja | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | ≤ 6.2.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpmanageninja | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | 0 ~ 6.2.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73533 | 9.8 CRITICAL | Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build |
| CVE-2026-73532 | 9.8 CRITICAL | Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build |
| CVE-2026-66467 | 6.5 MEDIUM | WordPress FluentCommunity plugin <= 2.7.5 - Cross Site Scripting (XSS) vulnerability |
No comments yet