CVE-2024-2771

CRITICAL EXPLOITED NUCLEI

Contact Form Plugin by Fluent Forms < 5.1.17 - Unauthenticated Limited Privilege Escalation

Title source: nuclei
STIX 2.1

Exploitation Summary

CVE-2024-2771 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including whale93. A Nuclei detection template is also available.

AI-analyzed exploit summary This PoC demonstrates a privilege escalation vulnerability in the Fluent Forms WordPress plugin via an unauthenticated REST API endpoint. It allows attackers to grant arbitrary users full management permissions or delete manager accounts.

Description

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to grant users with Fluent Form management permissions which gives them access to all of the plugin's settings and features. This also makes it possible for unauthenticated attackers to delete manager accounts.

Exploits (1)

nomisec WORKING POC
by whale93 · remote
https://github.com/whale93/CVE-2024-2771-PoC

This PoC demonstrates a privilege escalation vulnerability in the Fluent Forms WordPress plugin via an unauthenticated REST API endpoint. It allows attackers to grant arbitrary users full management permissions or delete manager accounts.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Contact Form – Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder ≤ 5.1.16
No auth needed
Prerequisites: WordPress site with Fluent Forms ≤ 5.1.16 active · Access to the site's REST API
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Contact Form Plugin by Fluent Forms < 5.1.17 - Unauthenticated Limited Privilege Escalation
CRITICALVERIFIEDby Sourabh-Sahu
FOFA: body="/wp-content/plugins/fluentform/"

Scores

CVSS v3 9.8
EPSS 0.0233
EPSS Percentile 81.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2024-05-20
CWE
CWE-862
Status published
Products (2)
fluentforms/contact_form < 5.1.17
techjewel/Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder < 5.1.16
Published May 18, 2024
Tracked Since Feb 18, 2026