Record summary

CVE-2024-2782 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to modify all of the plugin's settings.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 20, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 22, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress

Browse Fluent Forms / Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress
VulnCheckVersion data not supplied

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Browse techjewel / Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Default status: unaffected

CVE ListThrough 5.1.16affected

Proofs of concept

1

Repository PoCs

GitHubwhale93/CVE-2024-2782-PoCRepository PoCby whale93Stars: 0Not analyzed1 file

1.8 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHWordPress FluentForms <= 5.1.16 - Broken Access ControlCVSS 7.5

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to modify all of the plugin's settings.

Impact

Unauthenticated attackers can modify all Fluent Forms plugin settings including email configurations and other sensitive parameters.

Remediation

Update Contact Form Plugin by Fluent Forms to version 5.1.17 or later.

WeaknessesCWE-862
Authorsriteshs4hu
Template tagscvecve2024wordpresswp-pluginwpfluentformwpscanintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CPE: cpe:2.3:a:fluentforms:contact_form:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"/wp-content/plugins/fluentform/"
FOFA: body="/wp-content/plugins/fluentform/"

Source: ProjectDiscovery

References

3