CVE-2026-81296
moderateUnauthenticated Broken Access Control in Fluent Forms Pro Add On Pack (WordPress)
CVE-2026-81296 is an unauthenticated broken access control vulnerability (CWE-862, missing authorization) in the Fluent Forms Pro Add On Pack, the premium companion plugin to the Fluent Forms forms builder for WordPress. An attacker can trigger it over the network with no privileges and no user interaction by sending crafted HTTP requests to plugin endpoints that fail to verify the requester's authorization. Per the CVSS vector, the impact is on data integrity only: an unauthenticated attacker can modify data through the plugin without credentials, with no direct data disclosure or availability loss. Any WordPress site running the add-on in version 6.2.12 or earlier is affected. No public proof-of-concept is known, the EPSS exploitation probability is low at 0.2%, and the flaw is not in CISA KEV, so no exploitation has been observed so far.
What to do: Update the Fluent Forms Pro Add On Pack to a release newer than 6.2.12 (check the WPManageNinja changelog or the Patchstack advisory for the exact fixed version). Sites that cannot update immediately should consider temporarily deactivating the add-on or blocking unauthenticated requests to its endpoints via a WAF, and should review form settings and submitted entries for signs of unauthorized changes.
| WPManageNinja Fluent Forms Pro Add On Pack | <= 6.2.12 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.