Executive brief
FluentCRM Pro is a popular WordPress plugin for customer relationship management and email campaigns. A SQL injection vulnerability in the plugin allows authenticated attackers with author-level privileges to read, modify, or delete the entire database, including user accounts and sensitive customer data.
Technical details
The vulnerability is a SQL injection flaw in FluentCRM Pro versions up to 3.1.12, exploitable by users with WordPress author privileges. The injection point occurs in an author-level endpoint that fails to properly sanitize user input before constructing SQL queries. An attacker with author-level access (or who can create a low-privilege account) can craft malicious input to extract or manipulate the entire database. The vulnerability was patched in version 3.1.13.
Affected products
- WP ManageNinja FluentCRM Pro <= 3.1.12
Timeline
- 2026-08-24: disclosed: Published by Patchstack
- 2026-08-24: patched: Version 3.1.13 available