CVE-2026-11880: Unknown Fluent Forms
Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.
The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users.
Affected products
- Unknown Fluent Forms: before 6.2.1 (fixed in 6.2.1)
Published 2026-07-01. Last modified 2026-07-01.