Impact
Fluent Forms plugin for WordPress suffers from an incorrect authorization weakness (CWE‑863) that permits authenticated users with subscriber-level privileges to cancel any user’s subscription by submitting a crafted 'subscription_id' via the payment cancellation AJAX endpoint. Because the plugin fails to verify that the requester is the owner of the subscription, an attacker can terminate a different user’s active subscription, resulting in loss of service and potential revenue loss. Based on the description, it is inferred that the attacker does not need additional privileges beyond those associated with the subscriber role or higher, and no external system exploitation is required.
Affected Systems
WordPress sites that have installed the wpmanageninja:Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin versions 6.2.1 or earlier are affected. Any site using the subscription management feature of this plugin is vulnerable until the plugin is updated beyond the affected release.
Risk and Exploitability
The CVSS score of 5.4 classifies this flaw as moderate severity. Its exploitation requires an authenticated session and an AJAX request to the cancellation endpoint, so the risk is contained to users who are logged in with subscriber or higher roles. The EPSS score of < 1% indicates a very low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread attacks. Nonetheless, sites with a large subscriber base or valuable recurring revenue streams should treat this as a significant risk and apply the fix promptly.
OpenCVE Enrichment