Junglewise Threat Intelligence

CVE-2026-5395: WPManageNinja Fluent Forms IDOR in exportEntries

CVE-2026-5395 · Severity: high · CVSS 8.2 · Published 2026-05-14

Technologies: WPManageNinja Fluent Forms. Vendors: WPManageNinja.

Executive brief

Fluent Forms is a popular WordPress plugin used to create contact forms, surveys, and quizzes. A security flaw allows certain authorized users to bypass access controls and view form submissions they should not be able to see. This could lead to the unauthorized exposure of sensitive customer data, the extraction of information from other database tables, and the disclosure of internal database structures.

Technical details

The Fluent Forms plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to and including 6.2.0. This issue exists within the exportEntries function due to missing validation on a user-controlled key. An authenticated attacker with Fluent Forms manager-level access or higher can exploit this to bypass form-level access restrictions. This allows for the unauthorized viewing of form submissions, the exportation of data from arbitrary database tables, and the enumeration of database table names through error message disclosure. The vulnerability was addressed in a subsequent changeset.

Affected products

  • WPManageNinja Fluent Forms Up to and including 6.2.0

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: advisory

References

Related threats