Missing Authorization Vulnerability in Fluent Forms Pro Plugin for WordPress
CVE-2026-2899

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 March 2026

What is CVE-2026-2899?

The Fluent Forms Pro Add On Pack for WordPress has a vulnerability that allows unauthenticated attackers to delete arbitrary media attachments. This occurs due to insufficient authorization checks in the deleteFile() method of the Uploader class, which does not verify user capabilities or utilize nonce verification. As a result, the registration of AJAX actions via addPublicAjaxAction() exposes both authenticated and unauthenticated endpoints that can be exploited through the attachment_id parameter, posing a serious risk of unauthorized file deletion.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Fluent Forms Pro Add On Pack * <= 6.1.17

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Prickly Cactus
.