CVE-2024-4157 is a high-severity PHP Object Injection vulnerability affecting the Fluent Forms plugin for WordPress, impacting all versions up to and including 5.1.15. Authenticated attackers with contributor-level access and specific "View Form" and "Manage Form" permissions can inject PHP objects through untrusted input deserialization. This could lead to arbitrary file deletion, sensitive data retrieval, or remote code execution if a suitable POP chain exists. While exploitation requires specific permissions, it can be chained with CVE-2024-2771 to bypass this requirement. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.1.16CPE matchmatch criteria | cpe:2.3:a:fluentforms:contact_form:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.