PHP Object Injection Vulnerability in Fluent Forms by WordPress
CVE-2025-9260

6.5MEDIUM

What is CVE-2025-9260?

The Fluent Forms plugin for WordPress is susceptible to PHP Object Injection due to a flaw in the deserialization of untrusted input within the parseUserProperties function. This vulnerability impacts versions 5.1.16 to 6.1.1 and allows authenticated attackers, with at least Subscriber-level access, to inject malicious PHP Objects. Additionally, the presence of a chain of properties (POP chain) could permit attackers to read arbitrary files, with the potential for remote code execution if 'allow_url_include' is active on the server. Although a patch was released in version 6.1.0, it caused a fatal error due to a missing class import, making version 6.1.2 the most reliable and secure update.

Affected Version(s)

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 <= 6.1.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Craig Smith
.