Junglewise Threat Intelligence

CVE-2026-81296: Fluent Forms Pro Add-On Pack broken access control vulnerability

CVE-2026-81296 · Severity: high · CVSS 7.5 · Published 2026-08-31

Executive brief

Fluent Forms Pro Add-On Pack is a WordPress plugin that extends the Fluent Forms form-building tool. An unauthenticated attacker can bypass access controls to view and access pages or data they should not be permitted to access, potentially exposing sensitive user or business information without requiring a valid login.

Technical details

This is a broken access control vulnerability in the Fluent Forms Pro Add-On Pack WordPress plugin affecting versions 6.2.12 and earlier. The vulnerability allows unauthenticated attackers to access restricted pages or perform actions that should require proper authorization, likely due to missing or inadequate permission checks in the vulnerable component. No authentication is required to exploit this issue. The vulnerability was patched in version 6.2.13, and administrators should update immediately to remediate the issue.

Affected products

  • WP ManageNinja LLC Fluent Forms Pro Add-On Pack ≤ 6.2.12

Timeline

  • 2026-08-28: disclosed
  • 2026-08-28: patched: Patch available in version 6.2.13

References