Impact
Unauthenticated broken access control in Fluent Forms Pro Add On Pack plugin versions up to 6.2.12 allows an attacker to gain privileges and access protected resources without authentication. The vulnerability can enable a non‑privileged user to modify form settings, retrieve sensitive submission data, or perform administrative actions normally reserved for privileged users.
Affected Systems
The affected product is the Fluent Forms Pro Add On Pack plugin developed by WP Manage Ninja. Versions 6.2.12 and earlier are vulnerable; any site running these versions of the plugin is impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. The likely attack vector is through the web interface or plugin endpoints, where an attacker can send specially crafted requests without authenticating, leading to unauthorized access or modification of form configurations and data.
OpenCVE Enrichment