Subscriber Privilege Escalation in Fluent Forms Pro by WP Fluent Forms
CVE-2026-81297

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
31 August 2026

What is CVE-2026-81297?

A vulnerability in the Fluent Forms Pro Add On Pack versions up to 6.2.12 allows unauthorized users to escalate their privileges. This weakness can enable subscribers to gain elevated permissions, potentially leading to unauthorized access to sensitive functionalities or data. It is crucial for website administrators using this plugin to implement the latest security patches to safeguard against this risk.

Affected Version(s)

Fluent Forms Pro Add On Pack <= 6.2.12

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.