Junglewise Threat Intelligence

CVE-2026-78270: WP ManageNinja FluentCRM Pro SQL injection in author endpoint

CVE-2026-78270 · Severity: high · CVSS 7.6 · Published 2026-08-24

Vendors: WP ManageNinja.

Executive brief

FluentCRM Pro is a popular WordPress plugin for customer relationship management and email campaigns. A SQL injection vulnerability in the plugin allows authenticated attackers with author-level privileges to read, modify, or delete the entire database, including user accounts and sensitive customer data.

Technical details

The vulnerability is a SQL injection flaw in FluentCRM Pro versions up to 3.1.12, exploitable by users with WordPress author privileges. The injection point occurs in an author-level endpoint that fails to properly sanitize user input before constructing SQL queries. An attacker with author-level access (or who can create a low-privilege account) can craft malicious input to extract or manipulate the entire database. The vulnerability was patched in version 3.1.13.

Affected products

  • WP ManageNinja FluentCRM Pro <= 3.1.12

Timeline

  • 2026-08-24: disclosed: Published by Patchstack
  • 2026-08-24: patched: Version 3.1.13 available

References