Description
The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default configuration in which an administrator has created at least one Manager restricted to specific forms.
Published: 2026-07-02
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Fluent Forms WordPress plugin versions before 6.2.5 allow a Manager who has been granted permission to delete submission records to remove entries belonging to forms that the Manager is not authorized to manage. This flaw is an IDOR that permits privilege escalation and results in irreversible loss of application data, potentially compromising reporting and compliance records.

Affected Systems

WordPress sites installing Fluent Forms earlier than version 6.2.5 and that have configured a custom Manager role with form visibility restrictions. The vulnerability activates only when an administrator has overridden the default role to limit a Manager’s access to a subset of forms.

Risk and Exploitability

An attacker must first be authenticated as a Manager with permission to delete entries, typically through legitimate access to the system. Once authenticated, the Manager can target any form submission record regardless of the configured form restrictions. The EPSS score of less than 1% indicates a low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is therefore internal, requiring legitimate Manager credentials, and the impact remains limited to authenticated privileged users only.

Generated by OpenCVE AI on July 21, 2026 at 12:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Fluent Forms to version 6.2.5 or newer to implement the corrected authorization checks.
  • Review and tighten Manager role permissions so that each Manager can only access and delete entries for the forms they are explicitly assigned to manage.
  • Enable and monitor audit logging for form submission deletions to detect and investigate any unauthorized activity.

Generated by OpenCVE AI on July 21, 2026 at 12:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Fri, 17 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-639

Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-639

Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sun, 12 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 11 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Thu, 09 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-639

Wed, 08 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-639

Wed, 08 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Tue, 07 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Tue, 07 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Mon, 06 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Mon, 06 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sun, 05 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sun, 05 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 04 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 04 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Fri, 03 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Fri, 03 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Thu, 02 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Thu, 02 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default configuration in which an administrator has created at least one Manager restricted to specific forms.
Title Fluent Forms < 6.2.5 - Form Manager+ Cross-Form Submission Entry Deletion via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-02T12:54:19.224Z

Reserved: 2026-06-08T11:40:12.713Z

Link: CVE-2026-11578

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:30:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-639

    Authorization Bypass Through User-Controlled Key