PT-2025-49355 · WordPress · Fluent Forms
Published
2025-12-06
·
Updated
2025-12-06
·
CVE-2025-13748
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress versions up to and including 6.1.7
Description
The Fluent Forms plugin is susceptible to an Insecure Direct Object Reference issue. This occurs due to a lack of validation on a user-controlled key, specifically the
submission id parameter, within the confirmScaPayment() function. Unauthenticated attackers can exploit this to mark arbitrary submissions as failed by sending specially crafted requests to the API endpoint, provided they can determine a valid submission identifier.Recommendations
Update Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress to a version later than 6.1.7.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fluent Forms