What is CVE-2026-15962?
CVE-2026-15962 is a PHP Object Injection vulnerability discovered in the Fluent Forms Pro Add On Pack plugin for WordPress. Affecting all versions up to and including 6.2.6, it allows authenticated attackers with Subscriber-level access and above to inject PHP Objects via deserialization of untrusted input. Users are advised to update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-15962, WordPress üçün Fluent Forms Pro Add On Pack plaginində aşkarlanmış PHP Obyekt İnyeksiyası zəifliyidir. Bu zəiflik 6.2.6 versiyasına qədər olan bütün versiyalara təsir edir və autentifikasiya olunmuş (Subscriber səviyyəsindən yuxarı) istifadəçilərə PHP Obyekt inyeksiya etməyə imkan verir. İstifadəçilər plagini ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-502
FAQ1
How can I protect against the CVE-2026-15962 vulnerability?
You should update the Fluent Forms Pro Add On Pack plugin to the latest version, as the vulnerability affects all versions up to and including 6.2.6.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.