Description
The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users.
Published: 2026-07-01
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Fluent Forms WordPress plugin before version 6.2.1 fails to verify that the user requesting a subscription cancellation is the owner of the subscription. Because of this, any authenticated user with a low‑privilege account can delete another user’s subscription by providing a valid subscription identifier to the plugin’s cancellation endpoint. This flaw undermines the integrity of the subscription system, allowing an attacker to remove service access for other users without proper authorization.

Affected Systems

All installations of Fluent Forms running a version earlier than 6.2.1 are affected. If an organization’s sites continue to run the vulnerable plugin, the IDOR flaw is present and any logged‑in user can target other users’ subscriptions.

Risk and Exploitability

Exploitation requires only that the attacker be authenticated, as they can trigger the vulnerability by submitting a subscription identifier to the plugin’s cancellation endpoint. The EPSS score of < 1 % indicates a low likelihood of exploitation in the wild, while the CVSS score of 3.1 reflects a low severity impact on data integrity for affected installations. The vulnerability is not listed in the CISA KEV catalog, but that does not reduce the risk to installations that remain on vulnerable versions.

Generated by OpenCVE AI on July 16, 2026 at 11:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fluent Forms plugin to version 6.2.1 or later.
  • Limit cancellation privileges so that only administrators or designated users can cancel subscriptions until the patch is applied.
  • Implement logging or monitoring of subscription cancellation actions to detect anomalous or unauthorized cancellations.
  • Check the vendor’s website for updates or patches as a general best practice.

Generated by OpenCVE AI on July 16, 2026 at 11:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 11 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Fri, 10 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Wed, 08 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Tue, 07 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Mon, 06 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Sun, 05 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Sun, 05 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 04 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Fri, 03 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Thu, 02 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Thu, 02 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Thu, 02 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Wed, 01 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Wed, 01 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users.
Title Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-01T10:17:33.638Z

Reserved: 2026-06-10T13:23:48.881Z

Link: CVE-2026-11880

cve-icon Vulnrichment

Updated: 2026-07-01T10:17:30.256Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:00:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key