#fluentcrm

Lnk.Biolnkbio
2024-02-25

☄️☄️ A new integration for the LnkBio newsletter: FluentCRM: automatically sync leads collected on your linkinbio page to FluentCRM on WordPress

lnk.bio/linkin/fluentcrm-newsl

Karl Emil Nikkakarlemilnikka
2023-06-14

After initial mishandling of my vulnerability report, WPManageNinja did the right things: started a vulnerability disclosure program, partnered up with Patchstack, and hired a WordPress security consultant. They even launched a bug-bounty program.

fluentcrm.com/security-and-vul

Karl Emil Nikkakarlemilnikka
2023-06-12

Responsible disclosure of unpatched vulnerability CVE-2023-1430 in FluentCRM by WPManageNinja (with mitigation patch): github.com/karlemilnikka/CVE-2.

tl;dr Attackers can view and edit contact details in FluentCRM. WPManageNinja hasn’t patched the vulnerability within the 90-day responsible disclosure time window. I provide a mitigation snippet to prevent vulnerability exploitation while waiting for an official patch.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst