PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15962 techjewel CVE debrief

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.

Vendor
techjewel
Product
Fluent Forms Pro Add On Pack
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-26
Original CVE updated
2026-07-27
Advisory published
2026-07-26
Advisory updated
2026-07-27

Who should care

Administrators of WordPress installations using the Fluent Forms Pro Add On Pack plugin, especially those with user update integration enabled and user meta fields mapped, should be aware of this vulnerability and take immediate action to protect their sites.

Technical summary

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection due to the deserialization of untrusted input. This vulnerability allows authenticated attackers with Subscriber-level access and above to inject PHP objects. The presence of a POP chain further enables attackers to modify user passwords and potentially gain control of administrator accounts. Successful exploitation requires user update integration to be enabled and a user meta field to be mapped.

Defensive priority

High

Recommended defensive actions

  • Update the Fluent Forms Pro Add On Pack plugin to the latest version.
  • Disable user update integration if not required.
  • Review and restrict user meta field mappings.
  • Monitor for suspicious user account activities.
  • Implement additional security measures such as Web Application Firewall (WAF) rules to detect and prevent PHP object injection attempts.

Evidence notes

The CVE record was published on 2026-07-26T02:16:28.790Z and has not been modified since then. The NVD entry is currently in the 'Received' status. The vulnerability details were provided by [email protected].

Sources and references

Verified primary and authoritative sources

  • CVE-2026-15962 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-15962

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-15962 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15962

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.