Description
Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Broken access control allowing removal of critical client functionality
Action: Patch
AI Analysis

Impact

The vulnerability is an incorrect behavior order flaw in the WordPress FluentForm plugin that permits the removal of essential client functionality. This broken access control allows an attacker to bypass normal restrictions and eliminate features that clients rely on, effectively denying service or degrading the user experience. The flaw is classified under CWE‑696, indicating fluctuating program state due to improper verification of input state or behavior order.

Affected Systems

WordPress sites running the FluentForm plugin from any version up to 6.2.14 are affected. The issue is specific to the WP ManageNinja LLC FluentForm plugin and does not impact other plugins or core WordPress components.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. EPSS is not available, so the current probability of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack likely requires access to the plugin’s administrative interface or a lower‑privileged role that can trigger the removal action, though the precise vector is not detailed. Successful exploitation would enable an attacker to delete or disable key client‑facing features, undermining integrity and availability.

Generated by OpenCVE AI on October 1, 2026 at 14:32 UTC.

Remediation

Vendor Solution

Update the WordPress FluentForm plugin to the latest available version (at least 6.2.15).


OpenCVE Recommended Actions

  • Update the FluentForm plugin to version 6.2.15 or later to receive the fixed code
  • If an immediate update is not possible, restrict access to the FluentForm editor by disabling it for non‑administrator roles or removing the plugin altogether until a patch is applied
  • After applying the patch, verify that all previously removed client functionality has been restored and monitor logs for unexpected removals

Generated by OpenCVE AI on October 1, 2026 at 14:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14.
Title WordPress FluentForm plugin <= 6.2.14 - Broken Access Control vulnerability
Weaknesses CWE-696
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T16:29:37.061Z

Reserved: 2026-09-30T12:43:33.094Z

Link: CVE-2026-103353

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:26.003

Modified: 2026-10-01T17:17:18.553

Link: CVE-2026-103353

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:45:10Z

Weaknesses