CVE-2024-2782: Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to modify all of the plugin's settings.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2782?
CVE-2024-2782 has a medium severity rating due to unauthorized modification of data vulnerabilities.
How do I fix CVE-2024-2782?
To fix CVE-2024-2782, update the Fluent Forms plugin to the latest version beyond 5.1.17.
What versions are affected by CVE-2024-2782?
CVE-2024-2782 affects all versions of the Fluent Forms plugin for WordPress up to and including 5.1.16.
What type of vulnerability is CVE-2024-2782?
CVE-2024-2782 is a vulnerability that allows unauthorized data modification due to a missing capability check.
Who is impacted by CVE-2024-2782?
Users of the Fluent Forms Contact Form Plugin for WordPress are impacted by CVE-2024-2782.