CVE · Medium

CVE-2026-17567 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-17567 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.9 Authorization Bypass Through User-Controlled Key Medium 5.3 < 6.2.9 6.2.9 2026-07-30

CVE-2026-17567

A security flaw exists in versions of the Fluent Forms plugin for WordPress up through 6.2.8 due to inadequate verification of a user-supplied value associated with the 'transaction' parameter. As a result, attackers can attempt to guess valid transaction hashes without needing credentials, potentially accessing sensitive payment information belonging to other users such as names, email addresses, and order details.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.