Impact
The Fluent Forms WordPress plugin before version 6.2.1 fails to verify that the user requesting a subscription cancellation is the owner of the subscription. Because of this, any authenticated user with a low‑privilege account can delete another user’s subscription by providing a valid subscription identifier to the plugin’s cancellation endpoint. This flaw undermines the integrity of the subscription system, allowing an attacker to remove service access for other users without proper authorization.
Affected Systems
All installations of Fluent Forms running a version earlier than 6.2.1 are affected. If an organization’s sites continue to run the vulnerable plugin, the IDOR flaw is present and any logged‑in user can target other users’ subscriptions.
Risk and Exploitability
Exploitation requires only that the attacker be authenticated, as they can trigger the vulnerability by submitting a subscription identifier to the plugin’s cancellation endpoint. The EPSS score of < 1 % indicates a low likelihood of exploitation in the wild, while the CVSS score of 3.1 reflects a low severity impact on data integrity for affected installations. The vulnerability is not listed in the CISA KEV catalog, but that does not reduce the risk to installations that remain on vulnerable versions.
OpenCVE Enrichment