CVE · High

CVE-2024-2782 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.17

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2782 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.17 Missing Authorization High 7.5 < 5.1.17 5.1.17 2024-05-17

CVE-2024-2782

Fluent Forms through version 5.1.16 contains a vulnerability in its REST API endpoint for global settings that fails to verify user permissions. An attacker without authentication can exploit this flaw to change any of the plugin's configuration options. The issue affects the /wp-json/fluentform/v1/global-settings endpoint and was resolved in version 5.1.17.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.