Insecure Direct Object Reference in Fluent Forms Plugin for WordPress
CVE-2026-17567
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 July 2026
What is CVE-2026-17567?
The Fluent Forms plugin for WordPress has been identified to have an Insecure Direct Object Reference vulnerability, allowing unauthenticated users to exploit the 'transaction' parameter due to insufficient validation. Attackers can brute-force valid transaction hashes, gaining unauthorized access to sensitive payment receipt information of other users, including customer details, billing address, order items, payment method, and payment status. This exploitation is feasible without prior authentication, as the submission ID, form ID, and transaction creation time can be easily guessed, resulting in a manageable attack vector.
Affected Version(s)
Fluent Forms β Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 0 <= 6.2.8