CVE-2024-6518

fluentform <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 14,734 live websites that are affected by CVE-2024-6518.

Test my site




Affected Software

Product  Fluentform
Category Wordpress Plugins
Vulnerable Domains14,734 live websites (22.99% of Fluentform install base)
Vulnerable Versions
  • from 0 through 5.1.19
Vulnerable Versions Count95 versions ( 84.07% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 27, 2024
  • Updated - Aug 1, 2024

Credits

  • Joel Indra (finder)
  • Yoel Indra Apelansa (finder)

CVE-2024-6518 usage by Country

United States5,473 websites



Germany1,806 websites
France909 websites
GB703 websites
Cyprus588 websites
Poland368 websites
Russia287 websites
Netherlands279 websites
South Africa260 websites
Australia220 websites

CVE-2024-6518 usage by TLD

.com6,409 websites
.de682 websites
.org602 websites
.co.uk509 websites
.com.au375 websites
.com.br319 websites
.ru313 websites
.net306 websites
.pl295 websites
.nl289 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-6518

Top websites that are affected by CVE-2024-6518. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************************.***.mx United States*,***
*********************.com United States**,***
****.com United States**,***
************.com Indonesia**,***
**********.com France**,***
******.com United States**,***
******.eu Poland**,***
*******.com United States**,***
**************.com United States**,***
******.eu United States**,***
See full domain list

FAQ

CVE-2024-6518 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Fluentform
A total of 14,734 websites have been identified as vulnerable to CVE-2024-6518, discovered through global website indexing conducted by WebTechSurvey.
Fluentform is susceptible to CVE-2024-6518 vulnerability.
Fluentform versions before, and including, 5.1.19 are vulnerable to CVE-2024-6518.