← WordPress Vulnerabilities
WordPress security by component

Fluent Forms Pro Add On Pack

Fluent Forms Pro Add On Pack is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jul 26, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: fluent-forms-pro-add-on-pack

CVE-2026-15962: Fluent Forms Pro subscriber object injection can reset user passwords

Fluent Forms Pro Add On Pack through 6.2.6 deserializes attacker-controlled form data when the User Update integration is enabled and a user-meta field is mapped. A logged-in Subscriber can submit a serialized PHP object; when a suitable POP chain is present, processing the mapped meta value can change another user's password and potentially take over an administrator account. The CNA record and vendor changelog do not disclose the exact endpoint, action, parameter or PHP function involved.

PublishedJul 26, 2026
Known safe version6.2.7
Safe version
Jul 26, 2026 CVE-2026-15962
Fluent Forms Pro subscriber object injection can reset user passwords
Fluent Forms Pro Add On Pack through 6.2.6 deserializes attacker-controlled form data when the User Update integration is enabled and a user-meta field is mapped. A logged-in Subscriber can submit a serialized PHP object; when a suitable POP chain is present, processing the mapped meta value can change another user's password and potentially take over an administrator account. The CNA record and vendor changelog do not disclose the exact endpoint, action, parameter or PHP function involved.
6.2.7
CVE8.8
NVDPending
Mar 05, 2026 CVE-2026-2899
Fluent Forms Pro Add On Pack: A security weakness
Fluent Forms Pro Add On Pack is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Feb 27, 2026 CVE-2026-2428
Fluent Forms Pro Add On Pack: A security weakness
Fluent Forms Pro Add On Pack is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Feb 09, 2026 CVE-2026-0632
Fluent Forms Pro Add On Pack: Server-side request forgery
Fluent Forms Pro Add On Pack is affected by server-side request forgery. Exploitation requires at least subscriber-level access. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE5.4
NVDPending