PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15962 techjewel CVE debrief

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.

Vendor
techjewel
Product
Fluent Forms Pro Add On Pack
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-26
Original CVE updated
2026-07-26
Advisory published
2026-07-26
Advisory updated
2026-07-26

Who should care

Administrators of WordPress installations using the Fluent Forms Pro Add On Pack plugin, especially those with user update integration enabled and user meta fields mapped, should be aware of this vulnerability and take immediate action to protect their sites.

Technical summary

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection due to the deserialization of untrusted input. This vulnerability allows authenticated attackers with Subscriber-level access and above to inject PHP objects. The presence of a POP chain further enables attackers to modify user passwords and potentially gain control of administrator accounts. Successful exploitation requires user update integration to be enabled and a user meta field to be mapped.

Defensive priority

High

Recommended defensive actions

  • Update the Fluent Forms Pro Add On Pack plugin to the latest version.
  • Disable user update integration if not required.
  • Review and restrict user meta field mappings.
  • Monitor for suspicious user account activities.
  • Implement additional security measures such as Web Application Firewall (WAF) rules to detect and prevent PHP object injection attempts.

Evidence notes

The CVE record was published on 2026-07-26T02:16:28.790Z and has not been modified since then. The NVD entry is currently in the 'Received' status. The vulnerability details were provided by [email protected].

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-26T02:16:28.790Z and has not been modified since then. The NVD entry is currently in the 'Received' status.