Impact
The vulnerability is an Insecure Direct Object Reference in the FluentCart WordPress plugin that allows any authenticated user to act on another user’s subscription by providing the subscription identifier. The attacker can change the payment method, cancel, or re‑bind the subscription, effectively hijacking the customer’s payment flow. This lack of ownership validation leads to manipulation of billing information and potentially unauthorized charges.
Affected Systems
All installations of the FluentCart "A New Era of eCommerce" WordPress plugin with a version earlier than 1.4.0 are affected. No specific additional vendors or modules are listed. Users should verify that the plugin is not in the pre‑1.4.0 release line before applying a fix.
Risk and Exploitability
The CVSS score of 4.2 reflects a moderate severity, and the EPSS score of less than 1% indicates a low probability of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker must be authenticated to a user account and must know the target subscription identifier to exploit this IDOR. Because the attack requires knowledge of internal identifiers, it is considered a targeted threat rather than a widespread, high‑impact vulnerability.
OpenCVE Enrichment