cleantalk
Vulnerabilities and Security Researches

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder, 701b208668bba1168289bdd44ec221a9534e4139

Published on
Sep 08, 2023
Research Description
Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.0.9 Contact Form for Plugin by Fluent Forms <= 5.0.8 - Insecure Direct Object Reference The Contact Form for Plugin by Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.8 via the addIsRenderableFilter() function due to missing validation on the publication status of a form. This makes it possible for users to render and submit forms when the form is in an 'unpublished' state.
Affected versions
max 5.0.9.
Status
vulnerable