← Back

CVE-2026-0632

nvd nist
Published: Feb 9, 2026Modified: Feb 9, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: security@wordfence.com

Description

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

Timeline (5)

2/9/2026
5 changes
New CVE Received - Reference
12:15 PM
- -
+ https://www.wordfence.com/threat-intel/vulnerabilities/id/fd3bf470-f966-454d-8df3-0dec4682e883?source=cve
New CVE Received - Reference
12:15 PM
- -
+ https://fluentforms.com/docs/changelog/
New CVE Received - CWE
12:15 PM
- -
+ CWE-918
New CVE Received - CVSS V3.1
12:15 PM
- -
+ AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
New CVE Received - Description
12:15 PM
- -
+ The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.