Tag
high
advisory
Privilege Escalation in jshERP 3.6 via updateOneValueByKeyIdAndType
2 rules 3 TTPs 1 CVEjshERP 3.6 contains an improper access control vulnerability in the updateOneValueByKeyIdAndType endpoint allowing authenticated users to escalate privileges to tenant administrator.
jshERP +1
privilege-escalation
web-application
authorization-bypass
idor
insecure-direct-object-reference
2r
3t
1c
high
threat
Fluent Forms WordPress Plugin IDOR Vulnerability (CVE-2026-5395)
2 rules 2 TTPs 1 CVEThe Fluent Forms WordPress plugin through 6.2.0 is vulnerable to Insecure Direct Object Reference (IDOR), allowing authenticated users with manager-level access or higher to bypass form-level access controls, export arbitrary database tables, and enumerate table names via error messages, as tracked by CVE-2026-5395.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin <= 6.2.0
insecure-direct-object-reference
wordpress
fluentforms
cve-2026-5395
2r
2t
1c