PHP Object Injection Vulnerability in Fluent Forms by WordPress
CVE-2025-9260
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 September 2025
What is CVE-2025-9260?
The Fluent Forms plugin for WordPress is susceptible to PHP Object Injection due to a flaw in the deserialization of untrusted input within the parseUserProperties function. This vulnerability impacts versions 5.1.16 to 6.1.1 and allows authenticated attackers, with at least Subscriber-level access, to inject malicious PHP Objects. Additionally, the presence of a chain of properties (POP chain) could permit attackers to read arbitrary files, with the potential for remote code execution if 'allow_url_include' is active on the server. Although a patch was released in version 6.1.0, it caused a fatal error due to a missing class import, making version 6.1.2 the most reliable and secure update.
Affected Version(s)
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 <= 6.1.1