PT-2024-22058 · WordPress · Contact Form Plugin By Fluent Forms
Kun_19
+1
·
Published
2024-05-18
·
Updated
2025-09-19
·
CVE-2024-2782
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress versions up to, and including, 5.1.16
Description
The issue is related to a missing capability check on the "/wp-json/fluentform/v1/global-settings" REST API endpoint. This allows unauthenticated attackers to modify all of the plugin's settings.
Recommendations
For versions up to, and including, 5.1.16, update to a version higher than 5.1.16 to resolve the issue.
As a temporary workaround, consider restricting access to the "/wp-json/fluentform/v1/global-settings" API endpoint until a patch is available.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contact Form Plugin By Fluent Forms