CVE-2026-2428 | Fluent Forms Pro Add On Pack Plugin up to 6.1.17 on WordPress IPN Endpoint PayPalSettings.php authorization
A vulnerability identified as critical has been detected in Fluent Forms Pro Add On Pack Plugin up to 6.1.17 on WordPress. Affected by this vulnerability is an unknown functionality of the file PayPalSettings.php of the component IPN Endpoint. This manipulation causes missing authorization.
This vulnerability is tracked as CVE-2026-2428. The attack is possible to be carried out remotely. No exploit exists.