Impact
The vulnerability is an incorrect behavior order flaw in the WordPress FluentForm plugin that permits the removal of essential client functionality. This broken access control allows an attacker to bypass normal restrictions and eliminate features that clients rely on, effectively denying service or degrading the user experience. The flaw is classified under CWE‑696, indicating fluctuating program state due to improper verification of input state or behavior order.
Affected Systems
WordPress sites running the FluentForm plugin from any version up to 6.2.14 are affected. The issue is specific to the WP ManageNinja LLC FluentForm plugin and does not impact other plugins or core WordPress components.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS is not available, so the current probability of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack likely requires access to the plugin’s administrative interface or a lower‑privileged role that can trigger the removal action, though the precise vector is not detailed. Successful exploitation would enable an attacker to delete or disable key client‑facing features, undermining integrity and availability.
OpenCVE Enrichment