Description
Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
Published: 2026-08-31
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Subscriber Privilege Escalation occurs in the WordPress Fluent Forms Pro Add On Pack plugin versions up to 6.2.12, allowing an authenticated user with the subscriber role to raise their privileges within the WordPress installation. This flaw is rooted in improper restriction of operations within a component (CWE-266), enabling the user to perform actions beyond their authorized scope. The outcome is a loss of integrity for site management and heightened risk of further compromise. The description confirms that the vulnerability is limited to subscriber accounts and does not affect unauthenticated attackers directly.

Affected Systems

The affected product is WP Manage Ninja's Fluent Forms Pro Add On Pack plugin, with vulnerable releases up to and including 6.2.12. Only sites running these versions are at risk; newer releases (at least 6.2.13) contain the fix.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity level. The EPSS score is not available, so the current exploitation probability is unknown, but the lack of a KEV listing suggests it has not yet been widely exploited. The likely attack vector requires an authenticated subscriber account, so compromise is more probable in environments where malicious users have such roles or where credential leakage occurs. Given the high severity and potential for broader compromise, the risk warrants prompt action.

Generated by OpenCVE AI on August 31, 2026 at 21:25 UTC.

Remediation

Vendor Solution

Update the WordPress Fluent Forms Pro Add On Pack Plugin to the latest available version (at least 6.2.13).


OpenCVE Recommended Actions

  • Update the Fluent Forms Pro Add On Pack plugin to version 6.2.13 or later.
  • If an update is not immediately possible, disable the plugin or restrict its functionality until the patch can be applied.
  • Consider removing the plugin entirely if it is not needed for site operations.
  • Temporarily reduce subscriber role capabilities to the minimum necessary until the vulnerability is resolved.

Generated by OpenCVE AI on August 31, 2026 at 21:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpmanageninja
Wpmanageninja fluent Forms Pro Add On Pack
Vendors & Products Wordpress
Wordpress wordpress
Wpmanageninja
Wpmanageninja fluent Forms Pro Add On Pack

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
Title WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.12 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
Wpmanageninja Fluent Forms Pro Add On Pack
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-31T20:35:49.135Z

Reserved: 2026-08-26T17:33:34.891Z

Link: CVE-2026-81297

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T21:17:50.420

Modified: 2026-08-31T21:17:50.420

Link: CVE-2026-81297

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T23:30:06Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment