Junglewise Threat Intelligence

CVE-2026-78277: FluentCRM Pro subscriber SSRF vulnerability

CVE-2026-78277 · Severity: medium · CVSS 4.9 · Published 2026-08-24

Vendors: WP ManageNinja LLC.

Executive brief

FluentCRM Pro is a WordPress plugin for customer relationship management and email campaigns. An attacker with a subscriber account can exploit a server-side request forgery (SSRF) vulnerability to make the server connect to internal systems and potentially leak sensitive data from behind the firewall or access resources not normally exposed to the internet.

Technical details

A server-side request forgery (SSRF) vulnerability in FluentCRM Pro versions up to 3.1.12 allows authenticated subscriber-level users to forge requests from the vulnerable server to internal or restricted resources. The vulnerability requires subscriber-level authentication to exploit. By crafting malicious requests, attackers can bypass network access controls, probe internal services, and potentially exfiltrate sensitive data. The vulnerability has been patched in version 3.1.13.

Affected products

  • WP ManageNinja LLC FluentCRM Pro <= 3.1.12

Timeline

  • 2026-08-24: disclosed: Published by Patchstack
  • 2026-08-24: patched: Version 3.1.13 available

References

Related threats