GHSA-x2rq-2q3v-fw75MediumCVSS 6.1
The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form...
🔗 CVE IDs covered (1)
📋 Description
The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it.