Description
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
Published: 2026-08-24
Score: 4.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A server‑side request forgery flaw exists in WP ManageNinja LLC’s FluentCRM Pro plugin up to version 3.1.12. An attacker who can influence a subscriber entry can cause the plugin to issue HTTP requests to arbitrary URLs from the web server. This can lead to internal network enumeration or data exfiltration, but does not provide direct remote code execution. The weakness is identified as CWE‑918.

Affected Systems

WordPress sites running the FluentCRM Pro plugin version 3.1.12 or earlier, provided by WP ManageNinja LLC. All installations of the plugin with a version less than or equal to 3.1.12 are affected.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate impact. EPSS data is not available, so there is no published estimate of exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through crafted subscriber data that leads the plugin to fetch an attacker‑controlled address. Exploitation requires the ability to create or modify subscriber records, which may be restricted to users with sufficient permissions. The risk, while moderate, warrants timely remediation because SSRF can expose internal services if not mitigated.

Generated by OpenCVE AI on August 24, 2026 at 12:22 UTC.

Remediation

Vendor Solution

Update the WordPress FluentCRM Pro Plugin to the latest available version (at least 3.1.13).


OpenCVE Recommended Actions

  • Update the FluentCRM Pro plugin to version 3.1.13 or later.
  • If immediate update is not possible, disable subscriber creation functionality or restrict access to users until the patch is applied.
  • Configure the web application firewall or network firewall to block outbound requests from the WordPress instance to internal IP ranges and localhost addresses.

Generated by OpenCVE AI on August 24, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
Title WordPress FluentCRM Pro plugin <= 3.1.12 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T12:51:10.534Z

Reserved: 2026-08-24T07:38:04.147Z

Link: CVE-2026-78277

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T12:16:55.347

Modified: 2026-08-24T12:16:55.347

Link: CVE-2026-78277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T12:30:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)