Impact
The vulnerability in Fluent Forms occurs because the plugin fails to verify that a user is authorized to perform certain actions, enabling authenticated users with Custom-level or higher privileges to bypass security controls. This permits them to read private form submissions, alter submission statuses, permanently delete submissions, and change global settings, thereby exposing and potentially corrupting sensitive data.
Affected Systems
WordPress sites that have installed any version of the Fluent Forms plugin from wpmanageninja up to and including 6.2.5. Sites that grant users Custom or higher roles are affected because those users can trigger the bypass.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in KEV, suggesting a low current exploitation probability, but the requirement of authenticated access limits the threat to users who already hold privileged roles. Attacks would involve an attacker logging in with a Custom+ role or higher, then using the unauthorized permissions to access and modify form data and plugin settings. The lack of an official patch notice means users must rely on upgrading the plugin to a fixed release, while reducing Custom+ privileges can mitigate the risk until the patch is applied.
OpenCVE Enrichment