CVE-2026-78271 HIGH

CVE-2026-78271: WordPress FluentCRM Pro plugin <= 3.1.12 - Privilege Escalation vulnerability

Vendor Wp Manage Ninja
Product FluentCRM Pro
Weakness CWE-266
Published August 27, 2026
Last update August 27, 2026

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.

Explanation of Vulnerability in Simple Terms

02Summary

FluentCRM Pro versions up to 3.1.12 contain a privilege assignment flaw that allows high-privileged users to access sensitive data and modify site functionality. An authenticated administrator can read confidential information, alter critical settings, and disrupt service availability. Update to a version newer than 3.1.12 to resolve this issue.

What an attacker can do

03Attacker Capabilities

A high-privileged user can read sensitive data, modify site settings, and disrupt service availability.

Potential impact on your site

04Site Impact

Administrators with compromised credentials could expose customer data, alter CRM configurations, or cause downtime.

Conditions required to exploit

05Prerequisites

Attacker must have high-level administrative privileges on the site; no user interaction required.

Key dates

06Disclosure timeline

August 27, 2026 CVE published
August 27, 2026 Record updated