CVE-2026-81297

7.5

Manage Ninja · Fluent Forms Pro Add On Pack

A privilege escalation vulnerability in the Fluent Forms Pro Add On Pack plugin for WordPress allows authenticated subscribers to gain unauthorized administrative privileges.

Executive summary

A critical privilege escalation vulnerability in the Fluent Forms Pro Add On Pack plugin allows authenticated subscribers to achieve elevated access, posing a severe risk to site integrity.

Vulnerability

This vulnerability, categorized as CWE-266, involves incorrect privilege assignment within the plugin. An authenticated user with subscriber-level access can manipulate the system to escalate their permissions to an administrative level.

Business impact

Successful exploitation of this flaw allows a low-privileged subscriber to gain full administrative control over the WordPress environment. This could lead to complete system compromise, unauthorized data exfiltration, or the deployment of malicious code, severely impacting business operations and data security. With a CVSS score of 7.5, this high-severity flaw requires immediate attention to prevent unauthorized administrative actions.

Remediation

Immediate Action: Update the Fluent Forms Pro Add On Pack plugin to version 6.2.13 or later immediately to resolve the privilege assignment issue.

Proactive Monitoring: Review WordPress user account logs and audit trails for unexpected administrative role changes or suspicious actions performed by accounts that were previously assigned subscriber roles.

Compensating Controls: If immediate patching is not possible, temporarily deactivate the plugin or restrict access to the site to prevent low-privileged users from interacting with the vulnerable functionality.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

The risk posed by this privilege escalation vulnerability is significant due to the potential for full administrative takeover of the affected WordPress instance. Administrators must prioritize updating the Fluent Forms Pro Add On Pack to version 6.2.13 or higher to close the security gap. Failure to apply this update leaves the platform vulnerable to unauthorized access and potential compromise.

More Manage Ninja CVEs

Sources

Originally found and disclosed by Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program, per the CVE Program record.