PT-2024-22058 · WordPress · Contact Form Plugin By Fluent Forms

Kun_19

+1

·

Published

2024-05-18

·

Updated

2025-09-19

·

CVE-2024-2782

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress versions up to, and including, 5.1.16
Description The issue is related to a missing capability check on the "/wp-json/fluentform/v1/global-settings" REST API endpoint. This allows unauthenticated attackers to modify all of the plugin's settings.
Recommendations For versions up to, and including, 5.1.16, update to a version higher than 5.1.16 to resolve the issue. As a temporary workaround, consider restricting access to the "/wp-json/fluentform/v1/global-settings" API endpoint until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-2782

Affected Products

Contact Form Plugin By Fluent Forms