Impact
Fluent Forms versions lower than 6.2.5 expose an IDOR flaw that allows a Manager role, granted permission to delete submission records, to remove entries belonging to forms they are not authorized to manage. The authorization check is omitted during the delete operation, so the Manager can target any form ID. This results in irreversible loss of submission data, potentially erasing critical information gathered from users and undermining the integrity of the site’s data store. Based on the description, it is inferred that an attacker needs an authenticated Manager with delete privileges to exploit the flaw.
Affected Systems
WordPress installations that have the Fluent Forms plugin installed before version 6.2.5 and have configured a custom Manager role with restricted visibility over specific forms. The vulnerability activates only when the administrator has overridden the default role to limit a Manager’s access to a subset of forms, meaning all sites meeting these conditions are susceptible.
Risk and Exploitability
Based on the description, it is inferred that an attacker must first be authenticated as a Manager with delete privileges. If such a Manager exists in a system where the role is restricted to specific forms, the flaw permits internal exploitation. The EPSS score, less than 1%, suggests a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack path is internal, requiring legitimate Manager credentials; there is no publicly exploitable path for external actors.
OpenCVE Enrichment