Contact Form Plugin by Fluent Forms 漏洞列表
共找到 1 个与 Contact Form Plugin by Fluent Forms 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2024-2771: Contact Form Plugin by Fluent Forms < 5.1.17 - Unauthenticated Limited Privilege Escalation POC
The plugin is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint. This makes it possible for unauthenticated attackers to grant users with Fluent Form management permissions which gives them access to all of the plugin's settings and features. This also makes it possible for unauthenticated attackers to delete manager accounts.