Web / CMS

Cross-Site Scripting (XSS)

FluentForms <= 4.3.22 Stored XSS via Custom HTML fields

FluentForms <= 4.3.22 Stored XSS via Custom HTML fields The plugin does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with

5.4
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS69
PUBLISHED
2023-06-19
CVE IDs
CVE-2023-0546
VENDORS
WPManageNinja LLC
PUBLIC EXPLOIT
PoC public
CWE
CWE-79
PRODUCT
FluentForms (WordPress plugin)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

FluentForms <= 4.3.22 Stored XSS via Custom HTML fields

The plugin does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with roles as low as contributor to inject arbitrary javascript into a form which will trigger for any visitor to the form or admins previewing or editing the form.

Vulnerability details

Vulnerability details

CVE-2023-0546
CWE-79
Medium | 5.4

FluentForms <= 4.3.22 Stored XSS via Custom HTML fields The plugin does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with roles as low as contributor to inject arbitrary javascript

Auth:
Any authenticated user (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2023-01-24 Reported On

2023-03-20 Made Public On

2023-03-15 Fixed On

Credits

Vaibhav Rajput