WordPress security by component
Fluent Forms Pro Add On Pack
Plugin description
Fluent Forms Pro Add On Pack is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jul 26, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
fluent-forms-pro-add-on-packLatest vulnerability
CVE-2026-15962: Fluent Forms Pro subscriber object injection can reset user passwords
Fluent Forms Pro Add On Pack through 6.2.6 deserializes attacker-controlled form data when the User Update integration is enabled and a user-meta field is mapped. A logged-in Subscriber can submit a serialized PHP object; when a suitable POP chain is present, processing the mapped meta value can change another user's password and potentially take over an administrator account. The CNA record and vendor changelog do not disclose the exact endpoint, action, parameter or PHP function involved.
| Safe version |
|
||
|---|---|---|---|
| Jul 26, 2026 |
CVE-2026-15962
Fluent Forms Pro subscriber object injection can reset user passwords
Fluent Forms Pro Add On Pack through 6.2.6 deserializes attacker-controlled form data when the User Update integration is enabled and a user-meta field is mapped. A logged-in Subscriber can submit a serialized PHP object; when a suitable POP chain is present, processing the mapped meta value can change another user's password and potentially take over an administrator account. The CNA record and vendor changelog do not disclose the exact endpoint, action, parameter or PHP function involved.
|
6.2.7 |
CVE8.8
NVDPending
|
| Mar 05, 2026 |
CVE-2026-2899
Fluent Forms Pro Add On Pack: A security weakness
Fluent Forms Pro Add On Pack is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 27, 2026 |
CVE-2026-2428
Fluent Forms Pro Add On Pack: A security weakness
Fluent Forms Pro Add On Pack is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Feb 09, 2026 |
CVE-2026-0632
Fluent Forms Pro Add On Pack: Server-side request forgery
Fluent Forms Pro Add On Pack is affected by server-side request forgery. Exploitation requires at least subscriber-level access. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE5.4
NVDPending
|