The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (disable_ipn_verification defaults to yes in PayPalSettings.php). This makes it possible for unauthenticated attackers to send forged PayPal IPN notifications to the publicly accessible IPN endpoint, marking unpaid form submissions as paid and triggering post-payment automation (emails, access grants, digital product delivery).
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.