CyberRota Analysis
AI-GeneratedThe Fluent Forms WordPress plugin prior to version 6.2.6 is vulnerable due to inadequate sanitization of form field configuration settings, which can lead to Stored Cross-Site Scripting (XSS) attacks. This flaw allows users with Contributor roles, who have delegated form-management permissions, to inject malicious scripts that execute in the browsers of visitors and administrators previewing the forms. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it.