CVE-2025-9260 | Fluent Forms Plugin up to 5.1.16/6.1.0 on WordPress parseUserProperties deserialization
A vulnerability was found in Fluent Forms Plugin up to 5.1.16/6.1.0 on WordPress. It has been classified as critical. Impacted is the function parseUserProperties. Performing manipulation results in deserialization.
This vulnerability was named CVE-2025-9260. The attack may be initiated remotely. There is no available exploit.