S4E just found a high-severity finding from ssl robot vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 16, 2025

CVE-2024-2771 Scanner

CVE-2024-2771 Scanner - Privilege Escalation vulnerability in Contact Form Plugin by Fluent Forms

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-2771
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to grant users with Fluent Form management permissions which gives them access to all of the plugin's settings and features. This also makes it possible for unauthenticated attackers to delete manager accounts.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builderby techjewel
0
contact_formby fluentforms
0
Updated Aug 22, 2026View on NVD →
Detail

This scanner is designed for the Contact Form Plugin by Fluent Forms, a popular WordPress plugin used by website owners to create contact forms with ease. Website administrators and developers commonly leverage this plugin to enhance user interaction and collect visitor information efficiently. It provides users with a variety of configurations and customizations suited for diverse communication needs within websites. The plugin aims to integrate seamlessly with WordPress, offering an intuitive interface and an array of features to streamline form creation and management. Its widespread usage in the digital ecosystem makes it crucial to address vulnerabilities promptly to safeguard user data.

This vulnerability centers on a privilege escalation flaw due to an absent capability check on the REST API endpoint of the plugin. It allows unauthenticated attackers to exploit the API, enabling them to assign management permissions beyond intended limits. Such access grants them the ability to delve into plugin settings and features unauthorizedly, thereby heightening security risks. The flaw exists in versions of the plugin before 5.1.17, permitting potential manipulation of user privileges and compromising the security posture of the affected WordPress installations.

Technical details reveal that the vulnerable endpoint is '/wp-json/fluentform/v1/managers', which lacks adequate user access validation. Attackers can target this point with crafted requests to gain extra permissions on the plugin's settings. The flaw primarily involves missing authentication checks, which should restrict user roles to prevent unauthorized privilege allocation. As a result, malicious actors can escalate privileges by modifying specific parameters within the API calls, thus exerting control over sensitive plugin functionalities.

Potential effects of this vulnerability, if exploited, can lead to attackers gaining unwarranted access to various settings and data managed by the plugin, including sensitive user inputs. The exploitation allows unauthorized deletion of manager accounts, jeopardizing the integrity and confidentiality of the website data. Such unauthorized modifications can severely undermine the trustworthiness of the website and potentially lead to additional security breaches affecting user privacy.

REFERENCES

Solution Advice
  • Ensure that all WordPress installations using the Contact Form Plugin by Fluent Forms are updated to version 5.1.17 or later.
  • Restrict access to the /wp-json/fluentform/v1/managers endpoint to authenticated users only.
  • Regularly audit and manage user roles and access permissions within your WordPress admin panel.
  • Implement additional logging and monitoring on your WordPress site for unusual activities involving the form plugin.
  • Consider deploying security plugins that help to manage REST API access controls effectively.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.