Impact
The FluentCRM WordPress plugin contains a stored cross‑site scripting vulnerability in the 'fluentcrm_content' shortcode. This is a CWE‑79 vulnerability. Unsanitized, user‑supplied attributes allow an authenticated contributor or higher to embed malicious JavaScript that is stored and executed whenever a page containing the shortcode is viewed.
Affected Systems
WordPress sites running any version of the FluentCRM plugin up to and including 2.9.84. The plugin is made by Techjewel. Users with contributor‑level access or more are required to exploit the flaw.
Risk and Exploitability
The weakness is rated CVSS 6.4 with an EPSS of less than 1 %, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with contributor permissions or higher, who can then store arbitrary scripts that will run for anyone who views the compromised content.
OpenCVE Enrichment