Impact
The vulnerability allows authenticated users with contributor privileges to embed arbitrary web scripts into the "permission_message" shortcode attribute of the Fluent Forms plugin. Because the input is neither sanitized nor properly escaped, the malicious code is stored in the database and executed whenever a user accesses a page containing the injected form, potentially enabling theft of credentials, cookie hijacking, or other malicious activities within the site context.
Affected Systems
All releases of the Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress by techjewel that are version 6.2.1 or earlier are impacted. Newer versions contain the fix and are therefore not affected.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. No EPSS data is provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation at this time. However, the exploit requires a local authenticated attack via a contributor or higher role; an attacker who can edit forms can inject scripts that run in the browsers of any user who views the compromised form, compromising confidentiality and integrity of user sessions. The stored nature of the flaw means that the malicious payload remains until it is manually removed or the plugin is updated.
OpenCVE Enrichment