CVE-2026-15962: PHP Object Injection in Fluent Forms Pro (CVSS 8.8)
ID: 613e090d-7cdd-5b0f-b042-c8805e5f4072
STIX ID: report--613e090d-7cdd-5b0f-b042-c8805e5f4072
Feed Name: CosmicBytez Labs
**High-severity PHP Object Injection (CVE-2026-15962) in Fluent Forms Pro Add On Pack (<= 6.2.6)** — Authenticated users with Subscriber+ access can supply crafted serialized payloads to an unsafe unserialize() call, and if a POP chain is available (in the plugin/theme ecosystem) this can lead to arbitrary file deletion, file write (webshell), data exfiltration, or remote code execution; the report includes technical details, detection indicators, and remediation steps (update plugin, audit plugins, restrict registrations, deploy WAF rules).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
