Impact
The Fluent Forms WordPress plugin prior to version 6.2.1 fails to confirm that the user requesting a subscription cancellation is the subscription owner. Consequently, any authenticated user with a low‑privilege account can send a valid subscription identifier to the plugin’s cancellation endpoint and delete another user’s subscription. This flaw undermines the integrity of the subscription system, allowing attackers to remove service access for individuals without authorization.
Affected Systems
All installations of Fluent Forms running a version earlier than 6.2.1 are affected. If an organization’s sites continue to run the vulnerable plugin, the IDOR vulnerability is present and any logged‑in user can target other users’ subscriptions.
Risk and Exploitability
Exploitation requires only that the attacker be authenticated; they can trigger the vulnerability by providing a subscription identifier to the cancellation endpoint. The EPSS score of < 1 % indicates a low likelihood of exploitation in the wild, while the CVSS score of 3.1 reflects low severity on data integrity for affected installations. The vulnerability is not listed in the CISA KEV catalog, but the lack of listing does not mitigate the risk to installations that remain on vulnerable versions.
OpenCVE Enrichment