CVE-2026-81296

7.5

Manage Ninja · Fluent Forms Pro Add On Pack

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to an unauthenticated broken access control flaw, allowing unauthorized integrity impacts.

Executive summary

A critical broken access control vulnerability in the Fluent Forms Pro Add On Pack plugin allows unauthenticated attackers to perform unauthorized actions, potentially compromising data integrity.

Vulnerability

This vulnerability is classified as CWE-862, Missing Authorization, occurring because the plugin fails to perform adequate capability checks on sensitive functions. The flaw allows unauthenticated remote attackers to bypass access controls and modify data within the plugin environment.

Business impact

The exploitation of this vulnerability poses a significant risk to the integrity of business operations and data stored within the WordPress environment. Given the CVSS score of 7.5, which indicates high severity, unauthorized actors could manipulate form configurations or submission data, potentially leading to business process disruption or loss of sensitive customer information.

Remediation

Immediate Action: Update the Fluent Forms Pro Add On Pack plugin to version 6.2.13 or later immediately to resolve the missing authorization check.

Proactive Monitoring: Review WordPress access logs for unusual requests directed at plugin-specific endpoints, particularly those originating from unknown or unauthorized IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious traffic patterns targeting WordPress plugin endpoints until the update is applied.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

The high severity of this vulnerability, combined with the lack of required authentication for exploitation, necessitates immediate attention. Administrators must prioritize updating the Fluent Forms Pro Add On Pack to version 6.2.13 or higher to close this security gap and ensure the ongoing integrity of the application.

More Manage Ninja CVEs

Sources

Originally found and disclosed by Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program, per the CVE Program record.