CVE-2026-81296: WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.12 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Fluent Forms Pro Add On Pack pluginto a version that resolves this vulnerability.Fixed in 6.2.13
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or prior privileges to exploit it. The network attack vector and low attack complexity indicate it can be targeted remotely with relatively few prerequisites.
What versions should be treated as affected?
Fluent Forms Pro Add On Pack versions 6.2.12 and earlier are identified as affected. The provided information does not identify a fixed version.
What is the likely security impact?
The supplied vector assigns high impact to integrity and no impact to confidentiality or availability. This indicates the primary concern is unauthorized modification rather than data disclosure or service disruption.