WordPress Plugin Vulnerabilities

FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR

Description

The plugin does not verify that a subscription belongs to the requesting customer in several of its payment-method endpoints, allowing any authenticated customer to act on another customer's subscription (changing its payment method, or cancelling and re-binding it) when they know the target subscription identifier.

Proof of Concept

Affects Plugins

Fixed in 1.4.0

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Sanjorn Keeratirungsan
Submitter
Sanjorn Keeratirungsan
Verified
Yes

Timeline

Publicly Published
2026-07-07 (about 16 days ago)
Added
2026-07-07 (about 15 days ago)
Last Updated
2026-07-07 (about 15 days ago)

Other