Sceawere
Vulnerability Detail
CVE-2026-15178UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Fluent Forms Authorization Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 3h ago
- Vendor
- wpmanageninja
- Product
- Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Fluent Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.2.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Custom-level access and above, to read private form submissions, change submission statuses, permanently delete submissions, and modify global plugin settings.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-10T07:16:41.363Z",
"pubdate": "2026-10-10T07:16:41.363Z",
"executiveSummary": "The Fluent Forms plugin for WordPress is susceptible to an authorization bypass vulnerability affecting all versions up to and including 6.2.5. The vulnerability stems from improper validation of user permissions during the execution of sensitive administrative functions.\nThis security flaw allows authenticated users possessing at least Custom-level access to perform unauthorized actions, including the extraction of sensitive data from private form submissions, manipulation of submission statuses, permanent deletion of records, and modification of global plugin configurations.\nThe risk implication is significant as it permits an attacker to perform administrative operations without the required privileges, potentially leading to data breaches or the disruption of form submission services. Exploitation requires the attacker to have an active user account with a minimum of Custom-level privileges, meaning the attack vector is restricted to registered users within the application's environment. There is no evidence of anonymous exploitation, but the impact of an escalated session within the WordPress ecosystem poses a severe risk to data integrity and confidentiality.",
"technicalDetails": "The vulnerability originates from a deficiency in the access control logic within the Fluent Forms plugin, specifically concerning the validation of user capabilities before processing sensitive requests. The plugin fails to perform rigorous checks against the WordPress permission schema (the 'current_user_can()' function or similar capability verification mechanisms) when handling requests routed to submission management and plugin settings endpoints.\nBecause the plugin does not enforce strict role-based access control, any authenticated user assigned a role with Custom-level access or higher can bypass existing security filters. When a request is sent to the vulnerable backend controllers, the system incorrectly assumes the request originator possesses the requisite administrative rights based on the session token alone, without verifying the specific capability required for the targeted function.\nThe attack flow proceeds as follows: An attacker with valid credentials initiates an HTTP request (typically a GET or POST) directed at the plugin's submission management or settings endpoints. By manipulating request parameters or calling specific functions directly—which are intended to be restricted to Administrators—the attacker invokes the application logic to read, delete, or modify data. For example, by targeting specific submission IDs, an attacker can bypass the UI-level restrictions and access raw data via the server-side processing functions.\nThe scope of impact is comprehensive. By successfully bypassing authorization, an attacker can enumerate private submission data containing PII or other sensitive information, alter the business logic associated with form statuses, perform destructive actions such as purging the database of user entries, and reconfigure global plugin settings. This can be used to redirect form submissions, modify notification recipients, or alter spam filtering settings to facilitate further exploitation.\nThe vulnerable component involves the internal routing and request handling mechanisms responsible for processing administrative tasks. Given that these functions are exposed to authenticated users without appropriate capability checks, the plugin effectively grants an unauthorized escalation of privilege. This behavior is persistent across all versions up to and including 6.2.5, necessitating a security patch that implements explicit capability verification at the entry point of every sensitive administrative function."
}