CVE-2026-15962
Last modified
CVE-2026-15962 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| techjewel | Fluent Forms Pro Add On Pack | <= 6.2.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-15962?
How severe is CVE-2026-15962?
How do I fix CVE-2026-15962?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1594A security vulnerability has been detected in itsourcecode S…9.8
- CVE-2026-15943A flaw was found in the Keycloak keycloak-services component…5.5
- CVE-2026-15945A flaw was found in the group search functionality of the Ke…4.3
- CVE-2026-1595A vulnerability was detected in itsourcecode Society Managem…9.8
- CVE-2026-15957Smithy-RS is a Rust code generation and runtime framework th…8.7
- CVE-2026-1596A flaw has been found in D-Link DWR-M961 1.1.47. This vulner…8.8
- CVE-2026-15966Permissive cross-domain security policy with untrusted domai…9.8
- CVE-2026-15967Insufficient session expiration vulnerability in Progress MO…9.8
- CVE-2026-15968Improper neutralization of input during web page generation …5.4
- CVE-2026-15969SGLang contains an unauthenticated RCE in /load_lora_adapter…9.8
- CVE-2026-1597A vulnerability has been found in Bdtask SalesERP up to 2026…8.8
- CVE-2026-15971SGLang contains an RCE vulnerability when the optional dumpe…
Are you affected by CVE-2026-15962?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
