Security Advisory

CVE-2024-13666

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-22 08:24:17
Last updated 2026-04-08 17:28:42
Assigner Wordfence
State PUBLISHED

Description

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers spoof their IP address and submit forms that may have IP-based restrictions.