Insecure Direct Object Reference in Fluent Forms Plugin for WordPress
CVE-2026-5395
8.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 May 2026
What is CVE-2026-5395?
The Fluent Forms plugin for WordPress contains a vulnerability due to an Insecure Direct Object Reference in the exportEntries function. This flaw occurs in all versions up to and including 6.2.0, stemming from insufficient validation on a user-controlled key. It allows authenticated attackers with manager-level access or higher to bypass form-level access controls. Consequently, they can access restricted form submissions, export data from any database tables, and potentially enumerate table names via disclosed error messages.
Affected Version(s)
Fluent Forms β Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 0 <= 6.2.0