← WordPress Vulnerabilities
WordPress security by component

FluentCart A New Era of eCommerce

FluentCart A New Era of eCommerce is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 4.2.

Plugin slug: fluentcart-a-new-era-of-ecommerce

CVE-2026-14926: FluentCart customers can control other customers' subscriptions

FluentCart before 1.4.0 fails to verify that a subscription identifier belongs to the authenticated customer in several payment-method operations. A customer who learns another subscription identifier can change its payment method, cancel it or re-bind it, crossing the account ownership boundary. The WPScan CNA record does not disclose the endpoint paths, identifier parameter, ownership-check function or payment providers affected.

PublishedJul 28, 2026
Known safe version1.4.0
Safe version
Jul 28, 2026 CVE-2026-14926
FluentCart customers can control other customers' subscriptions
FluentCart before 1.4.0 fails to verify that a subscription identifier belongs to the authenticated customer in several payment-method operations. A customer who learns another subscription identifier can change its payment method, cancel it or re-bind it, crossing the account ownership boundary. The WPScan CNA record does not disclose the endpoint paths, identifier parameter, ownership-check function or payment providers affected.
1.4.0
CVE4.2
NVDPending