Authorization Bypass Vulnerability in Fluent Forms Plugin for WordPress
CVE-2026-15178
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-15178?
The Fluent Forms plugin for WordPress is susceptible to an authorization bypass across all versions up to and including 6.2.5. This security issue arises from insufficient checks on user permissions, allowing authenticated attackers with Custom-level access or higher to exploit this flaw. Attackers may gain access to read private form submissions, alter submission statuses, permanently delete submissions, and modify global plugin settings, posing a significant risk to data integrity and privacy.
Affected Version(s)
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 0 <= 6.2.5