Executive brief
The Fluent Forms Pro Add On Pack plugin for WordPress, which provides advanced form-building capabilities, contains a security flaw that allows logged-in users with basic permissions to execute malicious code. By exploiting this vulnerability, an attacker could change user passwords and take full control of administrator accounts. This risk is present only if the site has specific user update integrations enabled and configured.
Technical details
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 6.2.6. The vulnerability stems from the deserialization of untrusted input, which allows authenticated attackers with Subscriber-level permissions or higher to inject arbitrary PHP Objects. When combined with an existing POP (Property-Oriented Programming) chain, this can lead to unauthorized password changes and full administrative account takeover. Exploitation is conditional; it requires the 'user update integration' to be enabled and a user meta field to be mapped within the plugin settings.
Affected products
- techjewel Fluent Forms Pro Add On Pack up to, and including, 6.2.6
Timeline
- 2026-07-26: advisory: NVD publication date
- 2026-07-25: disclosed: Wordfence threat intelligence report