** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78270. Reason: This candidate is a reservation duplicate of CVE-2026-78270. Notes: All CVE users should reference CVE-2026-78270 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Upgrade FluentCRM Pro to version 3.1.13 or newer, which replaces the vulnerable query with parameterized statements that address the CWE‑89 flaw
- If an upgrade cannot be performed immediately, reduce the risk by revoking Author or higher roles from users who do not need to use the plugin’s functionality, thereby limiting the scope of the vulnerability
- Implement application‑level input validation or a firewall rule that blocks or sanitizes requests to the plugin’s endpoint, ensuring that only expected parameters are accepted
Generated by OpenCVE AI on August 25, 2026 at 20:59 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
No reference.
Thu, 03 Sep 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Fri, 28 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | FluentCRM Pro <= 3.1.12 - Authenticated (Author+) SQL Injection | |
| Metrics |
ssvc
|
Wed, 26 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78270. Reason: This candidate is a reservation duplicate of CVE-2026-78270. Notes: All CVE users should reference CVE-2026-78270 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. |
Tue, 25 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |
| Title | FluentCRM Pro <= 3.1.12 - Authenticated (Author+) SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: REJECTED
Assigner: Wordfence
Published:
Updated: 2026-08-26T16:47:00.702Z
Reserved: 2026-08-24T16:35:29.455Z
Link: CVE-2026-78468
Updated:
Status : Rejected
Published: 2026-08-25T17:18:17.500
Modified: 2026-09-03T05:13:15.267
Link: CVE-2026-78468
No data.
OpenCVE Enrichment
Updated: 2026-08-25T21:00:04Z
No weakness.