SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-11578

LOW · CVSS 2.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-07-02 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 2.7. It affects WordPress.

CVE
CVE-2026-11578
Severity
LOW
CVSS
2.7
EPSS
0.17%
WordPress

Original NVD Description

The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default configuration in which an administrator has created at least one Manager restricted to specific forms.