PT-2026-57057 · WordPress · Fluent Forms
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Fluent Forms versions prior to 6.2.2
Description
Insufficient ownership authorization checks in the payment cancellation AJAX flow allow authenticated attackers with subscriber-level access or higher to submit cancellation requests for subscriptions belonging to other users via the
subscription id parameter.Recommendations
Update Fluent Forms to version 6.2.2 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fluent Forms