CVE-2024-4709

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, and access granted by an administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 11,951 live websites that are affected by CVE-2024-4709.

Test my site




Affected Software

Product  Fluentform
Category Wordpress Plugins
Vulnerable Domains11,951 live websites (18.65% of Fluentform install base)
Vulnerable Versions
  • from 0 through 5.1.16
Vulnerable Versions Count92 versions ( 81.42% of all versions)



Details

  • Published - May 18, 2024
  • Updated - Aug 1, 2024

Credits

  • Tobias Weißhaar (finder)

CVE-2024-4709 usage by Country

United States4,358 websites



Germany1,486 websites
France766 websites
GB563 websites
Cyprus449 websites
Poland295 websites
Russia255 websites
Netherlands215 websites
South Africa214 websites
Australia180 websites

CVE-2024-4709 usage by TLD

.com5,101 websites
.de559 websites
.org510 websites
.co.uk403 websites
.com.au308 websites
.ru276 websites
.com.br258 websites
.net249 websites
.pl236 websites
.fr229 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4709

Top websites that are affected by CVE-2024-4709. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************************.***.mx United States*,***
*********************.com United States**,***
****.com United States**,***
************.com Indonesia**,***
**********.com France**,***
******.eu Poland**,***
*******.com United States**,***
**************.com United States**,***
***********.com United States**,***
*****.com United States**,***
See full domain list

FAQ

A total of 11,951 websites have been identified as vulnerable to CVE-2024-4709, discovered through global website indexing conducted by WebTechSurvey.
Fluentform is susceptible to CVE-2024-4709 vulnerability.
Fluentform versions before, and including, 5.1.16 are vulnerable to CVE-2024-4709.