CVE Database
/

CVE-2021-34620

Back to search

CVE-2021-34620

Published: Jul 7, 2021

Modified: Oct 15, 2024

PUBLISHED

Description

The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions

VendorProductVersions

WP Manage Ninja

WP Fluent Forms

affected
3.6.67 - < 3.6.67

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now