Impact
The Fluent Forms Pro Add On Pack plugin processes untrusted input that is deserialized by WordPress. Authenticated users with Subscriber level or higher can exploit this flaw to inject PHP objects. When the plugin’s user update integration is enabled and a user meta field is mapped, an attacker can supply a malicious payload that is unserialized and processed, allowing the payload to modify a user’s password stored in the meta table. This effectively grants the attacker control over the target account, including the potential to take over administrator accounts if the POP chain is present.
Affected Systems
WordPress sites using the Fluent Forms Pro Add On Pack plugin version 6.2.6 or earlier, developed by TechJewel. The vulnerability exists only when the user update integration feature is enabled and a user meta field mapping is configured.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity. The EPSS score is below 1%, which suggests that widespread exploitation is unlikely at present. It is not listed in the CISA KEV catalog, further indicating limited real-world exploitation. Attackers would need valid credentials for a WordPress account at Subscriber level or above and the plugin’s configuration that allows user meta updates. Once these conditions are satisfied, the PHP Object Injection can be used to change password fields, leading to possible account compromise and takeover of administrative privileges.
OpenCVE Enrichment