Description
The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the requesting customer in several of its payment-method endpoints, allowing any authenticated customer to act on another customer's subscription (changing its payment method, or cancelling and re-binding it) when they know the target subscription identifier.
Published: 2026-07-28
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Insecure Direct Object Reference in the FluentCart WordPress plugin that allows any authenticated user to act on another user’s subscription by providing the subscription identifier. The attacker can change the payment method, cancel, or re‑bind the subscription, effectively hijacking the customer’s payment flow. This lack of ownership validation leads to manipulation of billing information and potentially unauthorized charges.

Affected Systems

All installations of the FluentCart "A New Era of eCommerce" WordPress plugin with a version earlier than 1.4.0 are affected. No specific additional vendors or modules are listed. Users should verify that the plugin is not in the pre‑1.4.0 release line before applying a fix.

Risk and Exploitability

The CVSS score of 4.2 reflects a moderate severity, and the EPSS score of less than 1% indicates a low probability of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker must be authenticated to a user account and must know the target subscription identifier to exploit this IDOR. Because the attack requires knowledge of internal identifiers, it is considered a targeted threat rather than a widespread, high‑impact vulnerability.

Generated by OpenCVE AI on August 3, 2026 at 15:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the FluentCart plugin to version 1.4.0 or later where subscription ownership checks are implemented.
  • If an immediate update is not feasible, restrict access to the affected payment‑method endpoints or disable them for non‑admin users until a patch can be applied.
  • Verify that any custom or legacy code interacting with the plugin enforces ownership checks before allowing subscription modifications, and monitor logs for unauthorized access attempts.

Generated by OpenCVE AI on August 3, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Fluentcart
Fluentcart a New Era Of Ecommerce
Wordpress
Wordpress wordpress
Vendors & Products Fluentcart
Fluentcart a New Era Of Ecommerce
Wordpress
Wordpress wordpress

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the requesting customer in several of its payment-method endpoints, allowing any authenticated customer to act on another customer's subscription (changing its payment method, or cancelling and re-binding it) when they know the target subscription identifier.
Title FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR
References

Subscriptions

Fluentcart A New Era Of Ecommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-28T13:11:31.641Z

Reserved: 2026-07-07T09:14:07.886Z

Link: CVE-2026-14926

cve-icon Vulnrichment

Updated: 2026-07-28T13:11:11.647Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T07:16:41.617

Modified: 2026-07-28T16:07:15.840

Link: CVE-2026-14926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:30:03Z

Weaknesses