PT-2025-35641 · WordPress · Fluent Forms
Craig Smith
·
Published
2025-09-02
·
Updated
2025-09-03
·
CVE-2025-9260
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress versions 5.1.16 through 6.1.1
Description
The plugin is susceptible to PHP Object Injection due to deserialization of untrusted input within the
parseUserProperties function. Authenticated attackers with Subscriber-level access or higher can inject a PHP Object. The presence of a PHP Object Payload (POP) chain enables attackers to read arbitrary files. If allow url include is enabled on the server, remote code execution is possible.Recommendations
Update to version 6.1.2 or later.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fluent Forms