Description
The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users.
Published: 2026-07-01
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Fluent Forms WordPress plugin prior to version 6.2.1 fails to confirm that the user requesting a subscription cancellation is the subscription owner. Consequently, any authenticated user with a low‑privilege account can send a valid subscription identifier to the plugin’s cancellation endpoint and delete another user’s subscription. This flaw undermines the integrity of the subscription system, allowing attackers to remove service access for individuals without authorization.

Affected Systems

All installations of Fluent Forms running a version earlier than 6.2.1 are affected. If an organization’s sites continue to run the vulnerable plugin, the IDOR vulnerability is present and any logged‑in user can target other users’ subscriptions.

Risk and Exploitability

Exploitation requires only that the attacker be authenticated; they can trigger the vulnerability by providing a subscription identifier to the cancellation endpoint. The EPSS score of < 1 % indicates a low likelihood of exploitation in the wild, while the CVSS score of 3.1 reflects low severity on data integrity for affected installations. The vulnerability is not listed in the CISA KEV catalog, but the lack of listing does not mitigate the risk to installations that remain on vulnerable versions.

Generated by OpenCVE AI on August 4, 2026 at 08:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fluent Forms plugin to version 6.2.1 or later.
  • Restrict cancellation privileges so that only administrators or designated users can cancel subscriptions until the patch is applied.
  • Implement logging or monitoring of subscription cancellation actions to detect anomalous or unauthorized cancellations.

Generated by OpenCVE AI on August 4, 2026 at 08:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Wed, 29 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Wed, 29 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Fluent Forms
Fluent Forms fluent Forms
Wordpress
Wordpress wordpress
Vendors & Products Fluent Forms
Fluent Forms fluent Forms
Wordpress
Wordpress wordpress

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Wed, 22 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Tue, 14 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 11 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Fri, 10 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Wed, 08 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Tue, 07 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Mon, 06 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Sun, 05 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Sun, 05 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 04 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Fri, 03 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Thu, 02 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Thu, 02 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Thu, 02 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Wed, 01 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Wed, 01 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users.
Title Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR
References

Subscriptions

Fluent Forms Fluent Forms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-01T10:17:33.638Z

Reserved: 2026-06-10T13:23:48.881Z

Link: CVE-2026-11880

cve-icon Vulnrichment

Updated: 2026-07-01T10:17:30.256Z

cve-icon NVD

Status : Deferred

Published: 2026-07-01T07:16:22.487

Modified: 2026-07-01T18:17:52.013

Link: CVE-2026-11880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:15:06Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-639

    Authorization Bypass Through User-Controlled Key