CVE Published: 07/07/2021 |
CVE Updated: 15/10/2024 |
CVE Year: 2021 Source: Wordfence |
Vendor: WP Manage Ninja |
Product: WP Fluent Forms Status : PUBLISHED
CVE-2021-34620 Description
The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions