CVE-2026-0632: Fluent Forms Pro Add On Pack <= 6.1.12 - Authenticated (Subscriber+) Server-Side Request Forgery via 'saveDataSource'
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0632?
CVE-2026-0632 has a high severity rating due to its potential for Server-Side Request Forgery which can be exploited by authenticated users.
How do I fix CVE-2026-0632?
To fix CVE-2026-0632, update the Fluent Forms Pro Add On Pack plugin to version 6.1.13 or later.
What type of vulnerability is CVE-2026-0632?
CVE-2026-0632 is categorized as a Server-Side Request Forgery (SSRF) vulnerability.
Who is affected by CVE-2026-0632?
All users of Fluent Forms Pro Add On Pack versions up to and including 6.1.12 are affected by CVE-2026-0632.
Can CVE-2026-0632 be exploited remotely?
CVE-2026-0632 cannot be exploited remotely as it requires user authentication, specifically from users with Subscriber level or higher.