Junglewise Threat Intelligence

CVE-2026-81297: Fluent Forms Pro Add On Pack privilege escalation

CVE-2026-81297 · Severity: high · CVSS 7.5 · Published 2026-08-31

Executive brief

Fluent Forms Pro Add On Pack is a WordPress plugin that extends form creation and management capabilities. A privilege escalation vulnerability allows a low-privilege subscriber user to gain administrator access and take full control of a WordPress site, leading to potential data theft, malware injection, or site defacement.

Technical details

A privilege escalation vulnerability in Fluent Forms Pro Add On Pack versions 6.2.12 and earlier allows a subscriber-level user to escalate privileges to administrator. The vulnerability stems from insufficient access controls or authentication checks in a privileged function. An attacker with subscriber credentials (a low-privilege account) can exploit this remotely without additional user interaction to gain full administrative access. The patch is available in version 6.2.13 and later.

Affected products

  • WP ManageNinja LLC Fluent Forms Pro Add On Pack <= 6.2.12

Timeline

  • 2026-08-28: disclosed: Vulnerability publicly disclosed by Patchstack
  • 2026-08-28: patched: Patch released in version 6.2.13

References