Missing Authorization Vulnerability in Fluent Forms Pro Plugin for WordPress
CVE-2026-2899
6.5MEDIUM
What is CVE-2026-2899?
The Fluent Forms Pro Add On Pack for WordPress has a vulnerability that allows unauthenticated attackers to delete arbitrary media attachments. This occurs due to insufficient authorization checks in the deleteFile() method of the Uploader class, which does not verify user capabilities or utilize nonce verification. As a result, the registration of AJAX actions via addPublicAjaxAction() exposes both authenticated and unauthenticated endpoints that can be exploited through the attachment_id parameter, posing a serious risk of unauthorized file deletion.
Affected Version(s)
Fluent Forms Pro Add On Pack 0 <= 6.1.17