Sceawere
Vulnerability Detail
CVE-2026-94669UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Fluent Forms Pro Authorization Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 8h ago
- Vendor
- WP ManageNinja LLC
- Product
- Fluent Forms Pro Add On Pack
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-05T11:17:01.787Z",
"pubdate": "2026-10-05T11:17:01.787Z",
"executiveSummary": "The Fluent Forms Pro Add On Pack is susceptible to a Missing Authorization vulnerability, classified as an Improper Access Control issue. This vulnerability permits unauthorized entities to interact with sensitive functions or data that should be restricted based on security levels.\nThe vulnerability resides within the Fluent Forms Pro Add On Pack, affecting all versions from n/a through 6.2.13.\nThe primary risk involves an attacker bypassing configured access control security levels, potentially leading to unauthorized data access, unauthorized administrative actions, or unauthorized configuration modifications within the plugin's ecosystem.\nExploitation does not inherently require high-level administrative credentials, as the flaw originates from the failure to properly validate authorization tokens or user roles during request processing. An attacker with standard user access or, in some configurations, unauthenticated access, could potentially perform actions reserved for authorized personnel.\nThis vulnerability highlights a critical failure in the plugin's request handling logic, where security checks are either absent or improperly implemented for specific API endpoints or internal functions, thereby undermining the integrity of the application's authorization framework.",
"technicalDetails": "The vulnerability is rooted in an insufficient authorization check mechanism within the Fluent Forms Pro Add On Pack, specifically affecting versions n/a through 6.2.13. The defect manifests because certain functions or endpoints exposed by the plugin do not adequately verify the authorization levels of the requester before executing sensitive operations.\nIn the context of WordPress plugin development, this typically indicates that functions registered via hooks such as 'wp_ajax_' or 'wp_ajax_nopriv_'—or REST API endpoints defined via 'register_rest_route'—lack proper 'current_user_can()' checks or equivalent capability verification. When a request is received, the plugin proceeds to execute the logic without ensuring the caller possesses the necessary privileges to perform the specific action.\nThe attack flow begins when an attacker identifies the vulnerable endpoints within the Fluent Forms Pro Add On Pack. By crafting malicious HTTP requests (typically POST or GET requests) targeting these insufficiently protected entry points, an attacker can bypass the intended access control security levels. Because the server-side code fails to validate the user's role or authorization token before processing the request, the server treats the request as legitimate and executes the requested functionality.\nThe exploit allows an attacker to interact with the plugin's core features in an unauthorized manner. Depending on the specific endpoint exposed, this could involve viewing restricted forms, modifying configuration settings, exporting sensitive submission data, or triggering plugin-specific workflows that should only be accessible to administrators or authorized users. The absence of strict authorization checks means that the system blindly trusts the incoming request context.\nThe vulnerability is widespread across the affected versions, as it is a fundamental flaw in the implementation of the plugin's access control architecture. Post-exploitation, an attacker could potentially gain insight into sensitive form submissions, disrupt the operation of web forms, or leverage the plugin's functionality as a pivot point for further actions within the WordPress environment. This type of vulnerability is particularly dangerous because it bypasses the standard 'Security Level' configurations intended to restrict access, rendering those configuration settings ineffective."
}