WordPress · Fluent Forms · CVE-2026-5396
**Name of the Vulnerable Software and Affected Versions**
Fluent Forms versions prior to 6.1.22
**Description**
An authorization bypass exists in the `SubmissionPolicy` class, which authorizes submission-level actions such as reading, modifying, deleting, and adding notes based on a user-supplied `form id` query parameter. Authenticated attackers with Fluent Forms Manager access restricted to specific forms can spoof the `form id` parameter to access, modify the status of, add notes to, or permanently delete form submissions belonging to any other form.
**Recommendations**
Update to version 6.1.22 or later.