PULSE
LIVE34signals / 24h
FEED
ransomchaos reclama a remco.ca · CA · Otherransomqilin reclama a Contacto Garantido · MX · Professional Servicesransomqilin reclama a Universitatea de Vest „Vasile Goldiș” din Arad · RO · Educationransomm3rx reclama a hydraulic-components.net · DE · Manufacturingransomm3rx reclama a createinfor.pt · PT · Professional Servicesransomm3rx reclama a servicebypremier.com · US · Professional Servicesransomexfilsquad reclama a Analog Devices · US · Technologyransomexfilsquad reclama a Bonava · SE · Manufacturingransomexfilsquad reclama a City of Atlanta · US · Government & Defenseransomexfilsquad reclama a City of Houston · US · Government & Defenseransomexfilsquad reclama a Viavi Solutions · US · Technologyransomexfilsquad reclama a Newcastle University · GB · Educationransomexfilsquad reclama a District of Columbia Public Schools · US · Educationransomexfilsquad reclama a Zenith Bank Plc · NG · Financial Servicesransomchaos reclama a remco.ca · CA · Otherransomqilin reclama a Contacto Garantido · MX · Professional Servicesransomqilin reclama a Universitatea de Vest „Vasile Goldiș” din Arad · RO · Educationransomm3rx reclama a hydraulic-components.net · DE · Manufacturingransomm3rx reclama a createinfor.pt · PT · Professional Servicesransomm3rx reclama a servicebypremier.com · US · Professional Servicesransomexfilsquad reclama a Analog Devices · US · Technologyransomexfilsquad reclama a Bonava · SE · Manufacturingransomexfilsquad reclama a City of Atlanta · US · Government & Defenseransomexfilsquad reclama a City of Houston · US · Government & Defenseransomexfilsquad reclama a Viavi Solutions · US · Technologyransomexfilsquad reclama a Newcastle University · GB · Educationransomexfilsquad reclama a District of Columbia Public Schools · US · Educationransomexfilsquad reclama a Zenith Bank Plc · NG · Financial Services
← All CVEs
CVE WatchJul 26, 2026

CVE-2026-15962

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via

CVSS

8.8

High

EPSS

KEV

Exploit Today

0

0-100

Published: Jul 26, 2026 · Last modified: Jul 26, 2026 · CWE-502

EPSS · 30d

Not enough EPSS history yet.

Technical description

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if user update integration is enabled and a user meta field is mapped.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-505179.9 CRI
66.4%
20Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.1d
CVE-2026-21655
6.1%
2Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.2d
CVE-2026-654977.2 HIG
29.6%
9Administrator PHP Object Injection in Complianz <= 7.5.0 versions.3d
CVE-2026-654937.5 HIG
29.9%
9Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.3d
CVE-2026-595449.8 CRI
23.7%
7Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.3d
CVE-2026-167239.0 CRI
33.9%
10A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.3d