Vendor
Supply Chain Compromise of Fluent Forms Pro via Tampered Update Server
4 TTPs 1 CVEFluent Forms Pro 6.2.7 was compromised through a supply chain attack involving a decommissioned update server that served a tampered plugin build, leading to unauthorized backdoor access, persistence, and privilege escalation.
Stored XSS in Fluent Forms WordPress Plugin via Notification Smartcodes
2 TTPs 1 CVEAn unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Fluent Forms versions up to 6.2.11 allows attackers to inject malicious scripts that execute in the context of administrative users viewing submission logs.
Fluent Forms Pro Add On Pack Vulnerable to PHP Object Injection (CVE-2026-15962)
3 TTPs 1 CVEAn authenticated attacker with Subscriber-level access or higher can exploit a PHP Object Injection vulnerability in the Fluent Forms Pro Add On Pack plugin for WordPress, affecting versions up to and including 6.2.6. This deserialization of untrusted input, when combined with a POP chain, allows attackers to change user passwords and potentially achieve administrator account takeover. Exploitation is contingent on user update integration being enabled and a user meta field being mapped.