The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, and access granted by an administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 11,951 live websites that are affected by CVE-2024-4709.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 11,951 live websites (18.65% of Fluentform install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 92 versions ( 81.42% of all versions) |
![]() | 4,358 websites |
![]() | 1,486 websites |
![]() | 766 websites |
![]() | 563 websites |
![]() | 449 websites |
![]() | 295 websites |
![]() | 255 websites |
![]() | 215 websites |
![]() | 214 websites |
![]() | 180 websites |
.com | 5,101 websites |
.de | 559 websites |
.org | 510 websites |
.co.uk | 403 websites |
.com.au | 308 websites |
.ru | 276 websites |
.com.br | 258 websites |
.net | 249 websites |
.pl | 236 websites |
.fr | 229 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***************************.***.mx | ![]() | *,*** | |
*********************.com | ![]() | **,*** | |
****.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
******.eu | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
**************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*****.com | ![]() | **,*** |
FAQ