CVE-2026-5395 - Vulnerability Analysis
HighCVSS: 8.2Last Updated: May 14, 2026
Fluent Forms WordPress Plugin - Broken Access Control
Overview
Fluent Forms WordPress plugin <= 6.2.0 contains an insecure direct object reference caused by missing validation on a user-controlled key in exportEntries function, letting authenticated managers bypass form access restrictions and access unauthorized submissions.
Severity & Score
Impact
Authenticated attackers with manager-level access can access and export unauthorized form submissions and enumerate database tables.
Mitigation
Update to a version later than 6.2.0 or the latest available version.
References
Social Media Activity(2 posts)
š CVE-2026-5395 - High (8.2) The Fluent Forms ā Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to m... š https://www.thehackerwire.com/vulnerability/CVE-2026-5395/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-5395 - High (8.2) The Fluent Forms ā Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to m... š https://www.thehackerwire.com/vulnerability/CVE-2026-5395/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-5395
- Severity
- High
- CVSS Score
- 8.2
- Type
- broken_access_control
- Status
- rejected
- EPSS
- 3.0%
- Social Posts
- 2
CWE
- CWE-639
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N