The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in all versions up to, and including, 5.1.18. This makes it possible for Form Managers with a Subscriber-level access and above to modify the Mailchimp API key used for integration. At the same time, missing Mailchimp API key validation allows the redirect of the integration requests to the attacker-controlled server.
We have discovered 6,793 live websites that are affected by CVE-2024-5053.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 6,793 live websites (7.76% of Fluentform install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 57 versions ( 58% of all versions) |
| 1,694 websites | |
| 686 websites | |
| 475 websites | |
| 388 websites | |
| 220 websites | |
| 201 websites | |
| 199 websites | |
| 165 websites | |
| 162 websites | |
| 155 websites |
| .com | 2,752 websites |
| .de | 341 websites |
| .org | 294 websites |
| .co.uk | 232 websites |
| .fr | 156 websites |
| .pl | 156 websites |
| .com.au | 154 websites |
| .com.br | 149 websites |
| .net | 140 websites |
| .it | 139 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********************.com | **,*** | ||
| ************.com | **,*** | ||
| **********.com | **,*** | ||
| *******.com | **,*** | ||
| **************.com | **,*** | ||
| ******************.com | **,*** | ||
| ***.ci | **,*** | ||
| ***********.com | ***,*** | ||
| ***********.com | ***,*** | ||
| *******.com | ***,*** |
FAQ