CVE · Medium

CVE-2024-5053 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.19

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-5053 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.19 Improper Authorization Medium 4.3 < 5.1.19 5.1.19 2024-08-31

CVE-2024-5053

The Fluent Forms plugin for WordPress is susceptible to an improper authorization flaw that allows users with Subscriber-level permissions and higher to update the Mailchimp API key due to inadequate capability verification in the verifyRequest function. This vulnerability, present in versions up to 5.1.18, also lacks proper validation of the Mailchimp API key, enabling attackers to intercept integration requests and redirect them to malicious servers under their control.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.