WordPress security by component
FluentCart A New Era of eCommerce
Plugin description
FluentCart A New Era of eCommerce is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 4.2.
Plugin slug:
fluentcart-a-new-era-of-ecommerceLatest vulnerability
CVE-2026-14926: FluentCart customers can control other customers' subscriptions
FluentCart before 1.4.0 fails to verify that a subscription identifier belongs to the authenticated customer in several payment-method operations. A customer who learns another subscription identifier can change its payment method, cancel it or re-bind it, crossing the account ownership boundary. The WPScan CNA record does not disclose the endpoint paths, identifier parameter, ownership-check function or payment providers affected.
| Safe version |
|
||
|---|---|---|---|
| Jul 28, 2026 |
CVE-2026-14926
FluentCart customers can control other customers' subscriptions
FluentCart before 1.4.0 fails to verify that a subscription identifier belongs to the authenticated customer in several payment-method operations. A customer who learns another subscription identifier can change its payment method, cancel it or re-bind it, crossing the account ownership boundary. The WPScan CNA record does not disclose the endpoint paths, identifier parameter, ownership-check function or payment providers affected.
|
1.4.0 |
CVE4.2
NVDPending
|