The Fluent Forms Pro Add On Pack plugin for WordPress is...
High severity
Unreviewed
Published
Feb 27, 2026
to the GitHub Advisory Database
•
Updated Feb 27, 2026
Description
Published by the National Vulnerability Database
Feb 27, 2026
Published to the GitHub Advisory Database
Feb 27, 2026
Last updated
Feb 27, 2026
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (
disable_ipn_verificationdefaults to'yes'inPayPalSettings.php). This makes it possible for unauthenticated attackers to send forged PayPal IPN notifications to the publicly accessible IPN endpoint, marking unpaid form submissions as "paid" and triggering post-payment automation (emails, access grants, digital product delivery).References