CVE Database /
CVE-2024-5053
CVE · Medium
CVE-2024-5053 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.19
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-5053
|
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.19 |
Improper Authorization |
Medium
4.3
|
< 5.1.19
|
5.1.19 |
2024-08-31 |
—
|
CVE-2024-5053
The Fluent Forms plugin for WordPress is susceptible to an improper authorization flaw that allows users with Subscriber-level permissions and higher to update the Mailchimp API key due to inadequate capability verification in the verifyRequest function. This vulnerability, present in versions up to 5.1.18, also lacks proper validation of the Mailchimp API key, enabling attackers to intercept integration requests and redirect them to malicious servers under their control.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings