CVE-2026-11880: Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR
Published Jul 1, 2026
·Updated
The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users.
Affected Software
1 affected component
Fluent Forms WordPress plugin<6.2.1
Event History
Jul 1, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-11880?
The severity of CVE-2026-11880 is classified as low with a CVSS score of 3.1.
2
How do I fix CVE-2026-11880?
To fix CVE-2026-11880, update the Fluent Forms WordPress plugin to version 6.2.1 or later.
3
What type of vulnerability is CVE-2026-11880?
CVE-2026-11880 is an Insecure Direct Object Reference (IDOR) vulnerability.
4
Who is affected by CVE-2026-11880?
Authenticated users with low-privilege accounts can exploit CVE-2026-11880 to cancel subscriptions of other users.
5
What is the impact of CVE-2026-11880?
The impact of CVE-2026-11880 is that it allows unauthorized cancellation of user subscriptions, potentially disrupting services.