Key Vulnerability Information CVE: CVE-2026-2428 CVSS Score: 7.5 (High) Description: The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity due to the PayPal IPN (Instant Payment Notification) verification being disabled by default. This allows unauthenticated attackers to send forged PayPal IPN notifications, mark unpaid form submissions as "paid", and trigger post-payment automation. Publicly Published: February 26, 2026 Last Updated: February 27, 2026 Researcher: Prickly Cactus Remediation: Update to version 6.1.18 or a newer patched version. Affected Version: <= 6.1.17 Patched Version: 6.1.18 Recent Vulnerabilities Title: Fluent Forms Pro Add On Pack <= 6.1.12 - Authenticated (Subscriber+) Server-Side Request Forgery via 'saveDataSource' CVE ID: CVE-2026-0632 CVSS: 5.4 Researchers: andrea bocchetti Date: February 8, 2026