Junglewise Threat Intelligence

CVE-2026-78271: WP ManageNinja FluentCRM Pro privilege escalation in editor role

CVE-2026-78271 · Severity: high · CVSS 7.2 · Published 2026-08-27

Vendors: WP ManageNinja LLC.

Executive brief

FluentCRM Pro is a WordPress plugin for customer relationship management used by many small to medium-sized businesses. A privilege escalation flaw allows users with editor-level permissions to promote themselves to administrator and gain complete control of the website, including access to customer data, site configuration, and all sensitive operations.

Technical details

The vulnerability is a privilege escalation flaw in FluentCRM Pro versions 3.1.12 and earlier, classified as an identification and authentication failure (OWASP A7). A low-privilege user with editor role permissions can exploit this vulnerability to escalate privileges and become an administrator, gaining full control of the WordPress site. The attack requires the attacker to already have editor-level access; no network-based unauthenticated exploitation is possible. The vulnerability was patched in version 3.1.13. Patchstack has provided a mitigation rule to block exploit attempts until users can update.

Affected products

  • WP ManageNinja LLC FluentCRM Pro <= 3.1.12

Timeline

  • 2026-08-27: disclosed
  • 2026-08-25: patched: Patched in version 3.1.13

References

Related threats