Known CVE
WordPress FluentCRM <= 2.9.87 - Unauthenticated Blind SSRF
FluentCRM WordPress plugin <= 2.9.87 contains a blind server-side request forgery caused by improper validation of the 'SubscribeURL' parameter, letting unauthenticated attackers make arbitrary web requests, exploit requires unconfigured SES bounce handling key.
CVE-2026-7798
Medium2026CVSS 5.4CWE-918
cve2026 · wordpress · wp-plugin · fluentcrm · ssrf · wp
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website