WordPress Plugin Vulnerabilities
FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR
Description
The plugin does not verify that a subscription belongs to the requesting customer in several of its payment-method endpoints, allowing any authenticated customer to act on another customer's subscription (changing its payment method, or cancelling and re-binding it) when they know the target subscription identifier.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
ACCESS CONTROLS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Sanjorn Keeratirungsan
Submitter
Sanjorn Keeratirungsan
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-07 (about 16 days ago)
Added
2026-07-07 (about 15 days ago)
Last Updated
2026-07-07 (about 15 days ago)