plugin

Fluentformpro Vulnerabilities

10 known security issues reported for the Fluentformpro WordPress plugin. Most recent disclosed Aug 18, 2026.

1 critical 7 high 2 medium

Running Fluentformpro on your site? Check whether your installed version is affected.

Scan your site free

Fluent Forms Pro Add On Pack < 6.2.12 - Unauthenticated Stored Cross-Site Scripting

high

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 6.2.12. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a...

CVSS:
7.2
Affected:
up to 6.2.12
Fixed in:
6.2.12
Disclosed:
Aug 18, 2026

CVE-2026-66633 on NVD →

Fluent Forms Pro 6.2.7 & Ninja Tables Pro 5.2.13 - Remote Code Execution via Backdoor

critical

The Fluent Forms Pro in version 6.2.7 and the Ninja Tables Pro in version 5.2.13 plugins for WordPress are vulnerable to Remote Code Execution via Backdoor. This is due to threat actors compromised the vendor's system and embedded a backdoor into the plugin's code. This makes it possible for unauthenticated attackers t...

CVSS:
9.8
Affected:
6.2.7 – 6.2.7
Fixed in:
6.2.8
Disclosed:
Aug 3, 2026

Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field

high

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a...

CVSS:
8.8
Affected:
up to 6.2.6
Fixed in:
6.2.7
Disclosed:
Jul 25, 2026

CVE-2026-15962 on NVD →

Fluent Forms Pro Add On Pack - Unauthenticated Stored Cross-Site Scripting via Draft Form Submission vulnerability

high

Unauthenticated Stored Cross-Site Scripting via Draft Form Submission vulnerability

CVSS:
7.1
Affected:
up to 6.1.17
Fixed in:
6.1.18
Disclosed:
Mar 5, 2026

Fluent Forms Pro Add On Pack - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion vulnerability

high

Missing Authorization to Unauthenticated Arbitrary Attachment Deletion vulnerability

CVSS:
7.5
Affected:
up to 6.1.17
Fixed in:
6.1.18
Disclosed:
Mar 5, 2026

Fluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion

medium

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.17. This is due to the `deleteFile()` method in the `Uploader` class lacking nonce verification and capability checks. The AJAX action is registered via `addPublicAjaxAction()` which cr...

CVSS:
6.5
Affected:
up to 6.1.17
Fixed in:
6.1.18
Disclosed:
Mar 4, 2026

CVE-2026-2899 on NVD →

Fluent Forms Pro <= 6.1.17 - Unauthenticated Stored Cross-Site Scripting via Draft Form Submission

high

The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_save_data` AJAX action in all versions up to, and including, 6.1.17. This is due to the draft form submission endpoint being publicly accessible without authentication or nonce verification, combined wit...

CVSS:
7.2
Affected:
up to 6.1.17
Fixed in:
6.1.18
Disclosed:
Mar 4, 2026

CVE-2026-2365 on NVD →

Fluent Forms Pro Add On Pack - Missing Authorization to Unauthenticated Payment Status modification vulnerability

high

Missing Authorization to Unauthenticated Payment Status modification vulnerability

CVSS:
7.5
Affected:
up to 6.1.17
Fixed in:
6.1.18
Disclosed:
Feb 27, 2026

Fluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Payment Status modification

high

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (`disable_ipn_verification` defaults to `'yes'` in `PayP...

CVSS:
7.5
Affected:
up to 6.1.17
Fixed in:
6.1.18
Disclosed:
Feb 26, 2026

CVE-2026-2428 on NVD →

Fluent Forms Pro Add On Pack <= 6.1.12 - Authenticated (Subscriber+) Server-Side Request Forgery via 'saveDataSource'

medium

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations origi...

CVSS:
5.4
Affected:
up to 6.1.12
Fixed in:
6.1.13
Disclosed:
Feb 8, 2026

CVE-2026-0632 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database