WordPress security by component
Fluent Forms Pro Add-On Pack
Plugin description
Fluent Forms Pro Add-On Pack adds advanced form-building features and integrations to Fluent Forms.
Fluent Forms Pro Add-On Pack (fluentformpro) is a WordPress plugin with 4 published CVE records in this archive. The latest tracked vulnerability was published Aug 31, 2026; the highest published CVSS base score is 9.3.
Plugin slug:
fluentformproLatest vulnerability
CVE-2026-81297: Fluent Forms Pro permits Subscriber-level privilege escalation
Fluent Forms Pro Add On Pack through 6.2.12 allows a Subscriber to cross a privilege boundary and gain elevated permissions. The resulting unauthorized actions have high integrity impact.
| Safe version |
|
||
|---|---|---|---|
| Aug 31, 2026 |
CVE-2026-81297
Fluent Forms Pro permits Subscriber-level privilege escalation
Fluent Forms Pro Add On Pack through 6.2.12 allows a Subscriber to cross a privilege boundary and gain elevated permissions. The resulting unauthorized actions have high integrity impact.
|
6.2.13 |
CVE7.5
NVDPending
|
| Aug 31, 2026 |
CVE-2026-81296
Fluent Forms Pro exposes an unauthenticated state-changing operation
Fluent Forms Pro Add On Pack through 6.2.12 fails to authorize a protected operation. An unauthenticated request can invoke that operation and make a high-impact change to protected plugin or site state.
|
6.2.13 |
CVE7.5
NVDPending
|
| Aug 18, 2026 |
CVE-2026-66633
Fluent Forms Pro Add On Pack: Cross-site scripting
Fluent Forms Pro Add On Pack is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a to < 6.2.12.
|
6.2.12 |
CVE7.1
NVDPending
|
| Aug 13, 2026 |
CVE-2026-73532
Tampered Fluent Forms Pro 6.2.7 installs a persistent backdoor
A tampered Fluent Forms Pro 6.2.7 build distributed through the vendor's former update server added libs/class-license-sync.php and loaded it from fluentformpro.php. The rogue code exposed wp-update/v1, contacted apii.observer, planted PHP in mu-plugins and uploads, created passwordless administrator access and scheduled persistence that survives plugin removal. This is a supply-chain compromise rather than an ordinary request-validation flaw.
|
6.2.10 |
CVE9.3
NVDPending
|