Missing Authorization Vulnerability in Fluent Forms Pro Plugin for WordPress
CVE-2026-2899
What is CVE-2026-2899?
The Fluent Forms Pro Add On Pack for WordPress has a vulnerability that allows unauthenticated attackers to delete arbitrary media attachments. This occurs due to insufficient authorization checks in the deleteFile() method of the Uploader class, which does not verify user capabilities or utilize nonce verification. As a result, the registration of AJAX actions via addPublicAjaxAction() exposes both authenticated and unauthenticated endpoints that can be exploited through the attachment_id parameter, posing a serious risk of unauthorized file deletion.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fluent Forms Pro Add On Pack * <= 6.1.17
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved