CVE-2024-13666
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 22, 2025
CWE ID 20
Summary
CVE-2024-13666: The Fluent Forms plugin for WordPress, versions 5.2.12 and below, suffers from IP address spoofing vulnerability. Attackers can bypass IP-based restrictions by supplying fake HTTP headers, which are then used as the primary method for IP retrieval. This vulnerability allows unauthenticated attackers to spoof their IP addresses and potentially submit forms that should be restricted based on IP addresses. The insufficient IP address validation contributes to this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.