Retour à la veille
CVE-2026-16655
Score CVSS
7.2
HIGH
Description détaillée
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Vecteur d'attaque (CVSS)
Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Références et Patchs
https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.6/app/Hooks/Ajax.php#L17https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.6/app/Modules/Form/FormDataParser.php#L317https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.6/app/Modules/SubmissionHandler/SubmissionHandler.php#L20https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.6/app/Services/Form/SubmissionHandlerService.php#L123https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.6/app/Services/Integrations/GlobalNotificationService.php#L59https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.6/boot/globals.php#L110https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.7/app/Hooks/Ajax.php#L17https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.7/app/Modules/Form/FormDataParser.php#L317https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.7/app/Modules/SubmissionHandler/SubmissionHandler.php#L20https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.7/app/Services/Form/SubmissionHandlerService.php#L123https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.7/app/Services/Integrations/GlobalNotificationService.php#L59https://plugins.trac.wordpress.org/browser/fluentform/tags/6.2.7/boot/globals.php#L110https://plugins.trac.wordpress.org/changeset/3619584/fluentform/trunk/boot/globals.phphttps://plugins.trac.wordpress.org/changeset?old_path=%2Ffluentform/tags/6.2.7&new_path=%2Ffluentform/tags/6.2.8https://www.wordfence.com/threat-intel/vulnerabilities/id/635e19ba-da98-459c-ab91-ff969b0812fd?source=cve
Dernières Vulnérabilités
CVE-2026-65946
Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0
VOIR DÉTAILS
CVE-2026-65944
Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0
VOIR DÉTAILS
CVE-2026-65943
Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
VOIR DÉTAILS
