CVE-2026-78270: WordPress FluentCRM Pro plugin <= 3.1.12 - SQL Injection vulnerability
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress FluentCRM Pro pluginto a version that resolves this vulnerability.Fixed in 3.1.13
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is classified with PR:H, indicating that an attacker needs high privileges before exploitation. It is not described as exploitable by an unauthenticated or low-privileged user.
Can exploitation be performed remotely without user interaction?
Yes. The vector is AV:N and UI:N, meaning exploitation can occur over the network and does not require another user to take an action.
What security impact is indicated?
The issue may expose highly sensitive information, as indicated by C:H. Integrity impact is listed as none, while availability impact is low; the scope is changed (S:C).
Which FluentCRM Pro versions are identified as affected?
FluentCRM Pro versions 3.1.12 and earlier are identified as affected by the available data.