ZeroHour

CVE-2026-81297

large

Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack (WordPress)

CVSS 3.1
7.5 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-81297 is a privilege escalation flaw (CWE-266, incorrect privilege assignment) in the Fluent Forms Pro Add On Pack, the premium add-on for the Fluent Forms WordPress plugin. An attacker who already holds a subscriber-level account on an affected site — the lowest-privilege WordPress role, obtainable via open registration on many sites — can send crafted network requests to the plugin and be assigned higher privileges than intended. Successful escalation yields high impact to the site's confidentiality, integrity, and availability per the CVSS score (7.5, network vector, low privileges required, no user interaction, high attack complexity). Any WordPress site running the Pro Add On Pack at version 6.2.12 or earlier is affected. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and its EPSS score of 0.3% (23rd percentile) suggests low near-term exploitation risk.

What to do: Update the Fluent Forms Pro Add On Pack to the latest release, i.e., any version later than 6.2.12, via the vendor's plugin update mechanism (premium add-ons do not update from WordPress.org). Confirm the installed version under WP Admin > Plugins; as interim mitigation, disable or gate new user registrations and audit existing subscriber accounts, since exploitation requires a subscriber-level login. Monitor vendor advisories from WPManageNinja/Patchstack for the fixed version number and exploitation updates.

Affected
WPManageNinja Fluent Forms Pro Add On Pack<= 6.2.12
Estimated exposure
largetens of thousands of sites (premium add-on to the free Fluent Forms plugin, which has on the order of hundreds of thousands of active installs) — The Pro Add On Pack is the paid add-on for the widely installed free Fluent Forms plugin (roughly 300,000+ active installs), and premium add-ons typically deploy to only a fraction of the free plugin's user base, implying a plausible…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.

Ecosystems
WordPress
Weakness
CWE-266
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.