PT-2024-34307 · Unknown · Fluent Forms

·

CVE-2024-5053

·

Published

2024-09-01

·

Updated

2024-10-04

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Fluent Forms versions up to, and including, 5.1.18
Description: The issue is related to an insufficient capability check on the verifyRequest function, allowing Form Managers with a Subscriber-level access and above to modify the Mailchimp API key used for integration. Additionally, missing Mailchimp API key validation enables the redirect of integration requests to an attacker-controlled server.
Recommendations: For versions up to, and including, 5.1.18, update to the latest version of Fluent Forms to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the Mailchimp API key integration to prevent unauthorized modifications.

Fix

Improper Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-5053

Affected Products

Fluent Forms