Executive brief
FluentCart is an eCommerce plugin for WordPress that manages customer subscriptions and payments. A security flaw allows any logged-in customer to modify or cancel another customer's subscription if they know the subscription ID. This could lead to unauthorized service disruptions or changes to payment methods, potentially impacting business revenue and customer trust.
Technical details
The FluentCart plugin fails to perform proper authorization checks on several payment-method REST API endpoints. Specifically, the 'update-payment-method' and 'switch-payment-method' endpoints do not verify that the subscription ID provided in the request belongs to the authenticated user. An attacker with a valid customer account can exploit this Insecure Direct Object Reference (IDOR) vulnerability by sending crafted POST requests to these endpoints. If the attacker knows a victim's subscription UUID, they can trigger actions such as cancelling the original subscription or re-binding it to a different payment method. This issue is resolved in version 1.4.0.
Affected products
- WPScan FluentCart A New Era of eCommerce < 1.4.0
Timeline
- 2026-07-07: disclosed: Publicly published by WPScan
- 2026-07-28: advisory: CVE published to NVD dataset