PatchSiren cyber security CVE debrief
CVE-2026-15962 techjewel CVE debrief
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.
- Vendor
- techjewel
- Product
- Fluent Forms Pro Add On Pack
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-26
- Original CVE updated
- 2026-07-26
- Advisory published
- 2026-07-26
- Advisory updated
- 2026-07-26
Who should care
Administrators of WordPress installations using the Fluent Forms Pro Add On Pack plugin, especially those with user update integration enabled and user meta fields mapped, should be aware of this vulnerability and take immediate action to protect their sites.
Technical summary
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection due to the deserialization of untrusted input. This vulnerability allows authenticated attackers with Subscriber-level access and above to inject PHP objects. The presence of a POP chain further enables attackers to modify user passwords and potentially gain control of administrator accounts. Successful exploitation requires user update integration to be enabled and a user meta field to be mapped.
Defensive priority
High
Recommended defensive actions
- Update the Fluent Forms Pro Add On Pack plugin to the latest version.
- Disable user update integration if not required.
- Review and restrict user meta field mappings.
- Monitor for suspicious user account activities.
- Implement additional security measures such as Web Application Firewall (WAF) rules to detect and prevent PHP object injection attempts.
Evidence notes
The CVE record was published on 2026-07-26T02:16:28.790Z and has not been modified since then. The NVD entry is currently in the 'Received' status. The vulnerability details were provided by [email protected].
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-26T02:16:28.790Z and has not been modified since then. The NVD entry is currently in the 'Received' status.