---
id: CVE-2026-15962
title: >-
  The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP
  Object Injection in all versions up to, and including, 6.2.6 via
  deserialization of untrusted input
summary: >-
  The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP
  Object Injection in all versions up to, and including, 6.2.6 via
  deserialization of untrusted input. This makes it possible for authenticated
  attackers, with Subs…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
published: '2026-07-26'
updated: '2026-07-26'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15962'
references:
  - url: 'https://fluentforms.com'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/b95ec70c-ac76-48fa-9d9d-01cf1983e504?source=cve
    label: security@wordfence.com
tags:
  - nvd
ingestedAt: '2026-07-26T11:12:03.079Z'
epss: 0.00549
epssPercentile: 0.43548
---

## Overview

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
