Executive brief
Fluent Forms is a popular WordPress plugin used to create and manage contact forms and collect user submissions. A security flaw allows users with restricted administrative access to bypass permissions and view, modify, or delete form submissions belonging to other forms they should not be able to access. This could lead to the unauthorized exposure of sensitive customer data or the permanent loss of form records.
Technical details
The vulnerability exists within the SubmissionPolicy class, which incorrectly validates authorization for submission-level actions (read, modify, delete, add notes) based on a user-supplied 'form_id' query parameter. An authenticated attacker with 'Fluent Forms Manager' access—even if restricted to specific forms—can exploit this Insecure Direct Object Reference (IDOR) flaw by providing a 'form_id' for a form they are authorized to manage while targeting submissions belonging to a different, unauthorized form. This allows for unauthorized data exfiltration, status modification, and permanent deletion of form entries. The issue is addressed in version 6.2.0.
Affected products
- WPManageNinja Fluent Forms up to, and including, 6.1.21
Timeline
- 2026-05-14: disclosed
- 2026-05-14: advisory