Impact
The vulnerability is a missing authorization flaw in the FluentForm plugin. It allows attackers to bypass configured access control levels, potentially accessing or manipulating forms and data that should be restricted. This flaw maps to CWE‑862 and can lead to unauthorized disclosure, modification, or deletion of sensitive form content.
Affected Systems
All installations of the WordPress FluentForm plugin by Shahjahan Jewel using version 6.1.14 or earlier are affected. No version prior to 6.1.15 is vulnerable. The flaw spans from the earliest available release through the listed maximum version, and there is no known partial patch for intermediate releases.
Risk and Exploitability
The CVSS score of 4.3 reflects a low‑to‑moderate risk, and the EPSS score of less than 1% indicates a very low likelihood of exploitation in the field. The vulnerability is not present in CISA’s KEV catalog. The likely attack vector is a web attacker sending crafted HTTP requests to privileged plugin endpoints, exploiting the broken access control to read or modify form data without proper authorization. Because the flaw bypasses the plugin’s internal permission checks, an attacker with minimal or no credentials could potentially gain unauthorized access to sensitive forms or user data.
OpenCVE Enrichment