Fluent Forms Pro Add On Pack < 6.2.12 - Unauthenticated Stored Cross-Site Scripting
high
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 6.2.12. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a...
- CVSS:
- 7.2
- Affected:
- up to 6.2.12
- Fixed in:
- 6.2.12
- Disclosed:
- Aug 18, 2026
CVE-2026-66633 on NVD →
Fluent Forms Pro 6.2.7 & Ninja Tables Pro 5.2.13 - Remote Code Execution via Backdoor
critical
The Fluent Forms Pro in version 6.2.7 and the Ninja Tables Pro in version 5.2.13 plugins for WordPress are vulnerable to Remote Code Execution via Backdoor. This is due to threat actors compromised the vendor's system and embedded a backdoor into the plugin's code. This makes it possible for unauthenticated attackers t...
- CVSS:
- 9.8
- Affected:
- 6.2.7 – 6.2.7
- Fixed in:
- 6.2.8
- Disclosed:
- Aug 3, 2026
Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field
high
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a...
- CVSS:
- 8.8
- Affected:
- up to 6.2.6
- Fixed in:
- 6.2.7
- Disclosed:
- Jul 25, 2026
CVE-2026-15962 on NVD →
Fluent Forms Pro Add On Pack - Unauthenticated Stored Cross-Site Scripting via Draft Form Submission vulnerability
high
Unauthenticated Stored Cross-Site Scripting via Draft Form Submission vulnerability
- CVSS:
- 7.1
- Affected:
- up to 6.1.17
- Fixed in:
- 6.1.18
- Disclosed:
- Mar 5, 2026
Fluent Forms Pro Add On Pack - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion vulnerability
high
Missing Authorization to Unauthenticated Arbitrary Attachment Deletion vulnerability
- CVSS:
- 7.5
- Affected:
- up to 6.1.17
- Fixed in:
- 6.1.18
- Disclosed:
- Mar 5, 2026
Fluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion
medium
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.17. This is due to the `deleteFile()` method in the `Uploader` class lacking nonce verification and capability checks. The AJAX action is registered via `addPublicAjaxAction()` which cr...
- CVSS:
- 6.5
- Affected:
- up to 6.1.17
- Fixed in:
- 6.1.18
- Disclosed:
- Mar 4, 2026
CVE-2026-2899 on NVD →
Fluent Forms Pro <= 6.1.17 - Unauthenticated Stored Cross-Site Scripting via Draft Form Submission
high
The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_save_data` AJAX action in all versions up to, and including, 6.1.17. This is due to the draft form submission endpoint being publicly accessible without authentication or nonce verification, combined wit...
- CVSS:
- 7.2
- Affected:
- up to 6.1.17
- Fixed in:
- 6.1.18
- Disclosed:
- Mar 4, 2026
CVE-2026-2365 on NVD →
Fluent Forms Pro Add On Pack - Missing Authorization to Unauthenticated Payment Status modification vulnerability
high
Missing Authorization to Unauthenticated Payment Status modification vulnerability
- CVSS:
- 7.5
- Affected:
- up to 6.1.17
- Fixed in:
- 6.1.18
- Disclosed:
- Feb 27, 2026
Fluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Payment Status modification
high
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (`disable_ipn_verification` defaults to `'yes'` in `PayP...
- CVSS:
- 7.5
- Affected:
- up to 6.1.17
- Fixed in:
- 6.1.18
- Disclosed:
- Feb 26, 2026
CVE-2026-2428 on NVD →
Fluent Forms Pro Add On Pack <= 6.1.12 - Authenticated (Subscriber+) Server-Side Request Forgery via 'saveDataSource'
medium
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations origi...
- CVSS:
- 5.4
- Affected:
- up to 6.1.12
- Fixed in:
- 6.1.13
- Disclosed:
- Feb 8, 2026
CVE-2026-0632 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database