Junglewise Threat Intelligence

CVE-2026-57715: WPManageNinja Fluent CRM reflected XSS

CVE-2026-57715 · Severity: high · CVSS 7.1 · Published 2026-07-13

Vendors: WPManageNinja.

Executive brief

WPManageNinja Fluent CRM, a popular customer relationship management plugin for WordPress, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. This occurs when a user clicks on a specially crafted link, potentially leading to unauthorized actions being performed in the user's session, such as redirecting visitors to malicious sites or stealing sensitive information. Organizations using this plugin should update to the latest version to prevent potential site defacement or data theft.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the WPManageNinja Fluent CRM plugin for WordPress due to improper neutralization of input during web page generation. The flaw affects versions up to and including 3.1.7. An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser session, which can lead to session hijacking or unauthorized administrative actions if the victim is a site administrator. The issue is resolved in version 3.1.8.

Affected products

  • WPManageNinja Fluent CRM <= 3.1.7

Timeline

  • 2026-06-26: other: Vulnerability reported by researcher daroo
  • 2026-07-09: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD
  • 2026-07-13: patched: Patch confirmed available in version 3.1.8

References