CVE-2026-81297: WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.12 - Privilege Escalation vulnerability
Published Aug 31, 2026
·Updated
Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
Affected Software
1 affected component
Fluent Forms Fluent Forms Pro Add On Pack<=6.2.12
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Fluent Forms Pro Add On Packto a version that resolves this vulnerability.Fixed in 6.2.13
Event History
Aug 31, 2026
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs a subscriber-level account on a site running an affected version of the Fluent Forms Pro Add On Pack plugin. No user interaction is required.
2
Is this exploitable remotely?
Yes. The network attack vector indicates exploitation can be performed remotely, but it has high attack complexity and requires low-level privileges.
3
What security impact could successful exploitation have?
Successful exploitation could result in high impact to confidentiality, integrity, and availability, consistent with privilege escalation.