CVE Database /
CVE-2026-17567
CVE · Medium
CVE-2026-17567 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-17567
|
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.9 |
Authorization Bypass Through User-Controlled Key |
Medium
5.3
|
< 6.2.9
|
6.2.9 |
2026-07-30 |
—
|
CVE-2026-17567
A security flaw exists in versions of the Fluent Forms plugin for WordPress up through 6.2.8 due to inadequate verification of a user-supplied value associated with the 'transaction' parameter. As a result, attackers can attempt to guess valid transaction hashes without needing credentials, potentially accessing sensitive payment information belonging to other users such as names, email addresses, and order details.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings