Fluent Forms WordPress Plugin Insecure Direct Object Reference Vulnerability in Stripe SCA Confirmation
Vulnerability
A vulnerability exists in the Fluent Forms WordPress plugin, specifically in the Customizable Contact Forms, Survey, Quiz, and Conversational Form Builder versions up to and including 6.1.21. The issue is an Insecure Direct Object Reference (IDOR) that allows unauthenticated users to manipulate payment statuses of pending submissions. This vulnerability arises from a lack of proper authorization and ownership validation on the 'submission_id' parameter in the Stripe SCA confirmation AJAX endpoint.
Impact
Exploitation of this vulnerability allows for unauthorized modification of payment statuses on pending submissions, such as changing a status to 'failed'.
Remediation
Users can update to Fluent Forms version 6.2.0 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
