CVE

CVE-2026-11880 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-11880 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.1 Authorization Bypass Through User-Controlled Key Unknown < 6.2.1 6.2.1 2026-07-01

CVE-2026-11880

A security flaw in the Fluent Forms plugin for WordPress, versions prior to 6.2.1, allows certain users to terminate others' active subscriptions without proper authorization. This vulnerability arises from inadequate verification of user ownership when handling cancellation requests. As a result, users with lower privilege levels can still manipulate subscription statuses.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.