The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 14,734 live websites that are affected by CVE-2024-6518.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 14,734 live websites (22.99% of Fluentform install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 95 versions ( 84.07% of all versions) |
![]() | 5,473 websites |
![]() | 1,806 websites |
![]() | 909 websites |
![]() | 703 websites |
![]() | 588 websites |
![]() | 368 websites |
![]() | 287 websites |
![]() | 279 websites |
![]() | 260 websites |
![]() | 220 websites |
.com | 6,409 websites |
.de | 682 websites |
.org | 602 websites |
.co.uk | 509 websites |
.com.au | 375 websites |
.com.br | 319 websites |
.ru | 313 websites |
.net | 306 websites |
.pl | 295 websites |
.nl | 289 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***************************.***.mx | ![]() | *,*** | |
*********************.com | ![]() | **,*** | |
****.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
******.eu | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
**************.com | ![]() | **,*** | |
******.eu | ![]() | **,*** |
FAQ