Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw in the Fluent Forms Pro Add On Pack plugin. It allows an attacker to inject arbitrary JavaScript into web pages that users view, potentially enabling session hijacking, cookie theft, defacement or other client‑side malicious actions. The flaw can be leveraged without authentication, meaning any user visiting a vulnerable page could be affected.
Affected Systems
WPManageNinja’s Fluent Forms Pro Add On Pack plugin, versions older than 6.2.12. No other product variations or versions are listed.
Risk and Exploitability
A CVSS score of 7.1 classifies the issue as High severity. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified from the data, but the vulnerability is publicly known and could be widely used. The flaw is not listed in CISA’s KEV catalog. Because access is unauthenticated, attackers can exploit the weakness simply by sending a crafted request to a vulnerable form or configuration endpoint, with the malicious script being stored or delivered to other site users.
OpenCVE Enrichment