CVE · High

CVE-2026-5396 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-5396 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.0 Authorization Bypass Through User-Controlled Key High 8.2 < 6.2.0 6.2.0 2026-05-13

CVE-2026-5396

A security flaw exists in versions 6.1.21 and earlier of the Fluent Forms plugin for WordPress due to inadequate validation of user-submitted data. Specifically, the SubmissionPolicy class grants submission-level permissions based on a form ID provided by users through the query parameter. As a result, authorized attackers can manipulate this ID to access submissions from other forms they have permission to manage.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.