WordPress · Flo Forms · CVE-2026-12400
**Name of the Vulnerable Software and Affected Versions**
FlowForms – Conversational Form Builder versions prior to 1.1.2
**Description**
An Insecure Direct Object Reference (IDOR) exists in the `update form` function due to missing validation on a user-controlled key. Authenticated attackers with contributor-level access or higher can modify the content, design, and settings of any form on the site, including those owned by administrators, or publish and revert them by providing an arbitrary form ID in the REST URL.
**Recommendations**
Update FlowForms – Conversational Form Builder to version 1.1.2 or later.