CVE-2026-11880: Unknown Fluent Forms

Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.

The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users.

Affected products

  • Unknown Fluent Forms: before 6.2.1 (fixed in 6.2.1)

Published 2026-07-01. Last modified 2026-07-01.