CVE-2024-13666: Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers spoof their IP address and submit forms that may have IP-based restrictions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13666?
CVE-2024-13666 has been classified as a moderate severity vulnerability due to its potential to exploit IP address spoofing.
How do I fix CVE-2024-13666?
To fix CVE-2024-13666, update the Fluent Forms plugin to version 5.2.13 or later, which addresses the vulnerability.
What versions are affected by CVE-2024-13666?
CVE-2024-13666 affects all versions of Fluent Forms up to and including version 5.2.12.
What impact does CVE-2024-13666 have?
CVE-2024-13666 allows attackers to spoof IP addresses, potentially leading to unauthorized actions on the affected WordPress site.
Is there a work-around for CVE-2024-13666?
There are no recommended work-arounds for CVE-2024-13666 other than upgrading to the patched version.