CVE-2026-103353: WordPress FluentForm plugin <= 6.2.14 - Broken Access Control vulnerability
Published Oct 1, 2026
·Updated
Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14.
Affected Software
1 affected component
WP ManageNinja LLC FluentForm<=6.2.14
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress FluentForm pluginto a version that resolves this vulnerability.Fixed in 6.2.15
Event History
Oct 1, 2026
CVE Published
via MITRE·10:48 AM
Data Sourced
via MITRE·10:48 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploiting this issue require a WordPress account or user interaction?
No. The listed vector indicates network-based exploitation with no privileges required and no user interaction required.
2
How can I determine whether my site is potentially affected?
Check whether the site uses the WP ManageNinja LLC FluentForm plugin. Versions through 6.2.14 are identified as affected; the available data does not specify the earliest affected version.