Fluent Forms
cpe:2.3:a:fluentforms:contact_form:*:*:*:*:wordpress:*:*
- <= 6.1.7
A vulnerability exists in the Fluent Forms WordPress plugin, specifically in versions up to and including 6.1.7. The issue is an Insecure Direct Object Reference (IDOR) that allows unauthenticated attackers to manipulate payment statuses. This vulnerability arises from a lack of proper validation on the 'submission_id' parameter within the confirmScaPayment() function. Attackers can exploit this by sending crafted requests to the endpoint, potentially marking arbitrary submissions as failed, provided they can guess or enumerate valid submission identifiers.
Exploitation of this vulnerability allows for unauthorized tampering with payment submission statuses, marking them as failed without proper authorization.
Users are advised to update the Fluent Forms WordPress plugin to version 6.1.8 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.