Impact
Subscriber Privilege Escalation occurs in the WordPress Fluent Forms Pro Add On Pack plugin versions up to 6.2.12, allowing an authenticated user with the subscriber role to raise their privileges within the WordPress installation. This flaw is rooted in improper restriction of operations within a component (CWE-266), enabling the user to perform actions beyond their authorized scope. The outcome is a loss of integrity for site management and heightened risk of further compromise. The description confirms that the vulnerability is limited to subscriber accounts and does not affect unauthenticated attackers directly.
Affected Systems
The affected product is WP Manage Ninja's Fluent Forms Pro Add On Pack plugin, with vulnerable releases up to and including 6.2.12. Only sites running these versions are at risk; newer releases (at least 6.2.13) contain the fix.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level. The EPSS score is not available, so the current exploitation probability is unknown, but the lack of a KEV listing suggests it has not yet been widely exploited. The likely attack vector requires an authenticated subscriber account, so compromise is more probable in environments where malicious users have such roles or where credential leakage occurs. Given the high severity and potential for broader compromise, the risk warrants prompt action.
OpenCVE Enrichment