PT-2026-33318 · WordPress · Fluent Forms

Prickly Cactus

·

Published

2026-04-16

·

Updated

2026-04-17

·

CVE-2026-4160

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder versions prior to 6.1.22
Description An Insecure Direct Object Reference (IDOR) exists due to missing authorization and ownership validation on a user controlled key in the Stripe SCA confirmation AJAX endpoint. This allows unauthenticated attackers to modify the payment status of targeted pending submissions, such as changing the status to "failed", by manipulating the submission id parameter.
Recommendations Update the plugin to a version newer than 6.1.21. Avoid using the submission id parameter in the Stripe SCA confirmation AJAX endpoint until the update is applied.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4160

Affected Products

Fluent Forms