« Back to list

Fluentforms

Fluentforms Fluent Forms PRO ADD ON Pack: vulnerabilities and CVEs

Fluentforms Fluent Forms PRO ADD ON Pack has 5 published vulnerabilities, 5 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months5
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-81296High (7.5)0.35%—Aug 31, 2026
Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
CVE-2026-66633High (7.1)0.25%—Aug 18, 2026
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
CVE-2026-2899Medium (6.5)0.37%—Mar 5, 2026
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.17. This is due to the `deleteFile()` method in the `Uploader` class lacking nonce…
CVE-2026-2428High (7.5)0.14%—Feb 27, 2026
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment…
CVE-2026-0632Medium (5.4)0.24%—Feb 9, 2026
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application2
  2. T1059.007 JavaScript1
  3. T1078 Valid Accounts1
  4. T1189 Drive-by Compromise1
  5. T1565.003 Runtime Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Fluentforms