Impact
The Fluent Forms WordPress plugin versions before 6.2.5 allow a Manager who has been granted permission to delete submission records to remove entries belonging to forms that the Manager is not authorized to manage. This flaw is an IDOR that permits privilege escalation and results in irreversible loss of application data, potentially compromising reporting and compliance records.
Affected Systems
WordPress sites installing Fluent Forms earlier than version 6.2.5 and that have configured a custom Manager role with form visibility restrictions. The vulnerability activates only when an administrator has overridden the default role to limit a Manager’s access to a subset of forms.
Risk and Exploitability
An attacker must first be authenticated as a Manager with permission to delete entries, typically through legitimate access to the system. Once authenticated, the Manager can target any form submission record regardless of the configured form restrictions. The EPSS score of less than 1% indicates a low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is therefore internal, requiring legitimate Manager credentials, and the impact remains limited to authenticated privileged users only.
OpenCVE Enrichment