CVE-2026-4160Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownership validation on a user controlled key in the Stripe SCA confirmation AJAX endpoint. This makes it possible for unauthenticated attackers to modify payment status of targeted pending submissions (for example, setting the status to "failed").

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-17)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-16: 1Mentions · 2026-04-17: 2Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 204-1604-17
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-161
Disclosure1
2026-04-172
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4160 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via th… https://www.cve.org/CVERecord?id=CVE-2026-4160 ----- Traducción: CVE-2026-4160 El … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-4160, describing an insecure direct object reference flaw in the Fluent Forms WordPress plugin, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00000197
    71 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4160 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via th… https://www.cve.org/CVERecord?id=CVE-2026-4160

    Post summary

    The snippet announces CVE-2026-4160 for the Fluent Forms WordPress plugin, noting an Insecure Direct Object Reference vulnerability, but provides neither a PoC, exploitation details, nor a patch reference.

    00000284
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4160 Insecure Direct Object Reference in Fluent Forms WordPress Plugin Up To 6.1.21 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4160

    Post summary

    The entry announces CVE‑2026‑4160 as an IDOR vulnerability in Fluent Forms WP plugin up to v6.1.21, without providing exploit details or remediation guidance.

    0000039
    4.0K followersView on X

Explore more