fluentforms.com
https://fluentforms.com/docs/changelog CVE-2026-0632
MEDIUM
Fluent Forms Pro Add On Pack <= 6.1.12 - Authenticated (Subscriber+) Server-Side Request Forgery via 'saveDataSource'
Record summary
CVE-2026-0632 has a selected CVSS score of 5.4 (medium).
Description
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 9, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Fluent Forms Pro Add On PackBrowse techjewel / Fluent Forms Pro Add On PackDefault status: unaffected | CVE List | Through 6.1.12 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-0632 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/fd3bf470-f966-454d-8df3-0dec4682e883?source=cve