CVE-2026-15962
Received Received - Intake

PHP Object Injection in Fluent Forms Pro Add On Pack

Vulnerability report for CVE-2026-15962, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-26

Last updated on: 2026-07-26

Assigner: Wordfence

Description

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-26
Last Modified
2026-07-26
Generated
2026-07-26
AI Q&A
2026-07-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpmet fluent_forms_pro_add_on_pack to 6.2.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Fluent Forms Pro Add On Pack plugin for WordPress has a PHP Object Injection vulnerability in versions up to 6.2.6. This flaw allows authenticated attackers with Subscriber-level access or higher to inject a PHP Object through deserialization of untrusted input. If a POP chain exists, attackers can change user passwords and potentially take over administrator accounts. Exploitation requires user update integration to be enabled and a user meta field to be mapped.

Detection Guidance

Check for unauthorized user account changes or new admin accounts in WordPress. Review server logs for suspicious PHP Object Injection patterns or deserialization attempts. Use WordPress security plugins to scan for vulnerable plugin versions.

Impact Analysis

An attacker could exploit this to change user passwords, take over administrator accounts, and gain unauthorized access to the WordPress site. This could lead to data breaches, loss of sensitive information, or complete site compromise if the attacker escalates privileges.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, which may violate GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations could face legal penalties, reputational damage, and loss of customer trust if such breaches occur due to unpatched software.

Mitigation Strategies

Update the Fluent Forms Pro Add On Pack plugin to the latest version. Disable user update integration if enabled. Remove any unauthorized admin accounts. Monitor user accounts for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15962. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart