Subscriber Privilege Escalation in Fluent Forms Pro by WP Fluent Forms
CVE-2026-81297
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 August 2026
What is CVE-2026-81297?
A vulnerability in the Fluent Forms Pro Add On Pack versions up to 6.2.12 allows unauthorized users to escalate their privileges. This weakness can enable subscribers to gain elevated permissions, potentially leading to unauthorized access to sensitive functionalities or data. It is crucial for website administrators using this plugin to implement the latest security patches to safeguard against this risk.
Affected Version(s)
Fluent Forms Pro Add On Pack <= 6.2.12
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program