Fluent Forms WordPress Plugin Incorrect Authorization Vulnerability Allowing Arbitrary Subscription Cancellation

Vulnerability

A vulnerability exists in the Fluent Forms plugin for WordPress, specifically in versions through 6.2.1. The issue arises from inadequate authorization checks in the payment cancellation AJAX process, allowing authenticated users with subscriber-level access or higher to cancel subscriptions belonging to other users by manipulating the 'subscription_id' parameter.

Impact

Exploitation of this vulnerability allows for unauthorized cancellation of user subscriptions, potentially disrupting service or access for those users.

Remediation

Users can update to Fluent Forms version 6.2.2 or a newer patched version to address this vulnerability.

Added: Jul 10, 2026, 4:40 AM
Updated: Jul 10, 2026, 4:40 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
6.1
remediation
7.7
relevance
9.4
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.