SQL Injection Vulnerability in FluentCRM Pro for WordPress
CVE-2026-78468
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-78468?
The FluentCRM Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 3.1.12. This vulnerability arises from inadequate escaping of user-supplied parameters and insufficient query preparation, allowing authenticated attackers with Author-level access or higher to inject additional SQL queries into existing ones. This exploitation can lead to unauthorized data extraction from the database, posing a substantial risk to sensitive information stored within.
Affected Version(s)
FluentCRM Pro β Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution 0 <= 3.1.12