Description
Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
Published: 2026-08-27
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FluentCRM Pro versions up to 3.1.12 allow an authenticated editor to gain higher privileges by exploiting an improper privilege check within the plugin. This flaw can be leveraged to create or assign additional roles with the same level of access, effectively elevating the attacker’s capabilities while remaining within the WordPress environment. The vulnerability corresponds to CWE‑266, representing improper privilege management. Affected systems include the WordPress FluentCRM Pro plugin (WP Manage Ninja) version 3.1.12 and earlier. Administrators and site owners who have not upgraded to 3.1.13 or later are exposed to this escalation risk. The plugin is commonly used in WordPress installations backing customer relationship management workflows. The CVSS score of 7.2 reflects a medium‑high severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, indicating a lower publicly observed exploitation probability at present. Nonetheless, the lack of official exploitation reports does not diminish the need for timely remediation, as the flaw directly impacts role‑based access control within the WordPress ecosystem.

Affected Systems

The WordPress FluentCRM Pro plugin (WP Manage Ninja) versions up to and including 3.1.12 are affected. Site owners using one or more installations of these plugin versions should evaluate their current WordPress role configurations.

Risk and Exploitability

Assessment shows that the vulnerability is exploitable by users with editor or higher privileges in the WordPress environment. The attack requires the attacker to authenticate as an editor and then use the plugin’s API to create or reassign capabilities. There is no documented requirement for network‑level exploitation, and the source code indicates no remote code execution is necessary. Given the medium‑high CVSS, the risk remains significant and remediation should be prioritized.

Generated by OpenCVE AI on August 27, 2026 at 10:26 UTC.

Remediation

Vendor Solution

Update the WordPress FluentCRM Pro Plugin to the latest available version (at least 3.1.13).


OpenCVE Recommended Actions

  • Update the WordPress FluentCRM Pro Plugin to version 3.1.13 or newer.
  • Revoke or adjust any editor or higher‑privilege accounts that should not have access to the plugin’s functions.
  • Apply the principle of least privilege to WordPress user roles accessing the plugin, ensuring only necessary capabilities are granted.

Generated by OpenCVE AI on August 27, 2026 at 10:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
Title WordPress FluentCRM Pro plugin <= 3.1.12 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-27T12:18:28.265Z

Reserved: 2026-08-24T07:37:56.725Z

Link: CVE-2026-78271

cve-icon Vulnrichment

Updated: 2026-08-27T12:18:25.039Z

cve-icon NVD

Status : Received

Published: 2026-08-27T10:16:37.133

Modified: 2026-08-27T13:18:37.483

Link: CVE-2026-78271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T10:30:06Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment