Record summary

CVE-2024-2771 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to grant users with Fluent Form management permissions which gives them access to all of the plugin's settings and features. This also makes it possible for unauthenticated attackers to delete manager accounts.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 20, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 8, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress

Browse Fluent Forms / Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress
VulnCheckVersion data not supplied

Default status: unknown

CVE ListThrough 5.1.16affected

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Browse techjewel / Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Default status: unaffected

CVE ListThrough 5.1.16affected

Proofs of concept

1

Repository PoCs

GitHubwhale93/CVE-2024-2771-PoCRepository PoCby whale93Stars: 0Not analyzed1 file

2.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALContact Form Plugin by Fluent Forms < 5.1.17 - Unauthenticated Limited Privilege EscalationCVSS 9.8

The plugin is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint. This makes it possible for unauthenticated attackers to grant users with Fluent Form management permissions which gives them access to all of the plugin's settings and features. This also makes it possible for unauthenticated attackers to delete manager accounts.

Impact

Unauthenticated attackers can grant Fluent Form management permissions to any user account, providing access to all plugin settings and sensitive data.

Remediation

Update Contact Form Plugin by Fluent Forms to version 5.1.17 or later.

WeaknessesCWE-862
AuthorsSourabh-Sahu
Template tagscvecve2024wordpressfluentformswp-pluginunauthwpvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:fluentforms:contact_form:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/fluentform/"

Source: ProjectDiscovery

References

3