PT-2025-35641 · WordPress · Fluent Forms

·

CVE-2025-9260

·

Published

2025-09-02

·

Updated

2025-09-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress versions 5.1.16 through 6.1.1
Description The plugin is susceptible to PHP Object Injection due to deserialization of untrusted input within the parseUserProperties function. Authenticated attackers with Subscriber-level access or higher can inject a PHP Object. The presence of a PHP Object Payload (POP) chain enables attackers to read arbitrary files. If allow url include is enabled on the server, remote code execution is possible.
Recommendations Update to version 6.1.2 or later.

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9260

Affected Products

Fluent Forms