CVE · Medium

CVE-2025-13748 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13748 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.8 Authorization Bypass Through User-Controlled Key Medium 5.3 < 6.1.8 6.1.8 2025-12-05

CVE-2025-13748

The Fluent Forms plugin, up to version 6.1.7, is susceptible to Insecure Direct Object Reference vulnerabilities through the 'submission_id' parameter in the confirmScaPayment() function. Attackers without authentication can exploit this by crafting requests to mark any submission as failed if they can guess or enumerate a valid submission ID.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.