Description
Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
Published: 2026-08-31
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated broken access control in Fluent Forms Pro Add On Pack plugin versions up to 6.2.12 allows an attacker to gain privileges and access protected resources without authentication. The vulnerability can enable a non‑privileged user to modify form settings, retrieve sensitive submission data, or perform administrative actions normally reserved for privileged users.

Affected Systems

The affected product is the Fluent Forms Pro Add On Pack plugin developed by WP Manage Ninja. Versions 6.2.12 and earlier are vulnerable; any site running these versions of the plugin is impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. The likely attack vector is through the web interface or plugin endpoints, where an attacker can send specially crafted requests without authenticating, leading to unauthorized access or modification of form configurations and data.

Generated by OpenCVE AI on August 31, 2026 at 21:25 UTC.

Remediation

Vendor Solution

Update the WordPress Fluent Forms Pro Add On Pack Plugin to the latest available version (at least 6.2.13).


OpenCVE Recommended Actions

  • Update the WordPress Fluent Forms Pro Add On Pack Plugin to the latest version, at least 6.2.13
  • Remove or disable the plugin if it is not required for business operations
  • Review and tighten role permissions for WordPress users to limit unnecessary access to plugin functions

Generated by OpenCVE AI on August 31, 2026 at 21:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpmanageninja
Wpmanageninja fluent Forms Pro Add On Pack
Vendors & Products Wordpress
Wordpress wordpress
Wpmanageninja
Wpmanageninja fluent Forms Pro Add On Pack

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
Title WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.12 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Wordpress Wordpress
Wpmanageninja Fluent Forms Pro Add On Pack
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-31T20:35:47.966Z

Reserved: 2026-08-26T17:33:34.891Z

Link: CVE-2026-81296

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T21:17:50.297

Modified: 2026-08-31T21:17:50.297

Link: CVE-2026-81296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T22:00:05Z

Weaknesses