CVE-2026-57715
HIGHWordPress Fluent CRM plugin <= 3.1.7 - Cross Site Scripting (XSS) vulnerability
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-57715. PoCs published by incogbyte.
AI-analyzed exploit summary Reflected XSS vulnerability in FluentCRM <= 3.1.7 via unsanitized array keys in the `with[]` query parameter of the campaign detail REST endpoint. The exploit demonstrates how attacker-controlled markup flows unescaped into JSON error responses due to improper sanitization of array keys.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinja Fluent CRM fluent-crm allows Reflected XSS.This issue affects Fluent CRM: from n/a through <= 3.1.7.
Exploits (1)
Reflected XSS vulnerability in FluentCRM <= 3.1.7 via unsanitized array keys in the `with[]` query parameter of the campaign detail REST endpoint. The exploit demonstrates how attacker-controlled markup flows unescaped into JSON error responses due to improper sanitization of array keys.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L