PT-2026-57057 · WordPress · Fluent Forms

·

CVE-2026-5069

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Fluent Forms versions prior to 6.2.2
Description Insufficient ownership authorization checks in the payment cancellation AJAX flow allow authenticated attackers with subscriber-level access or higher to submit cancellation requests for subscriptions belonging to other users via the subscription id parameter.
Recommendations Update Fluent Forms to version 6.2.2 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5069

Affected Products

Fluent Forms