ZeroHour

CVE-2026-81296

moderate

Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack (WordPress)

CVSS 3.1
7.5 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-81296 is an unauthenticated broken access control vulnerability (CWE-862, missing authorization) in the Fluent Forms Pro Add On Pack, the premium companion plugin to the Fluent Forms forms builder for WordPress. An attacker can trigger it over the network with no privileges and no user interaction by sending crafted HTTP requests to plugin endpoints that fail to verify the requester's authorization. Per the CVSS vector, the impact is on data integrity only: an unauthenticated attacker can modify data through the plugin without credentials, with no direct data disclosure or availability loss. Any WordPress site running the add-on in version 6.2.12 or earlier is affected. No public proof-of-concept is known, the EPSS exploitation probability is low at 0.2%, and the flaw is not in CISA KEV, so no exploitation has been observed so far.

What to do: Update the Fluent Forms Pro Add On Pack to a release newer than 6.2.12 (check the WPManageNinja changelog or the Patchstack advisory for the exact fixed version). Sites that cannot update immediately should consider temporarily deactivating the add-on or blocking unauthenticated requests to its endpoints via a WAF, and should review form settings and submitted entries for signs of unauthorized changes.

Affected
WPManageNinja Fluent Forms Pro Add On Pack<= 6.2.12
Estimated exposure
moderate≈ tens of thousands of WordPress sites (estimated) — No public active-install count exists for this paid add-on, but the free Fluent Forms plugin it extends has hundreds of thousands of WordPress.org active installs and premium add-on tiers typically deploy on a minority of those sites,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.

Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.