Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesFluent Forms

Fluent Forms vulnerabilities

Fluent Forms has 38 known vulnerabilities in this database. The most recent published record is dated 1 Oct 2026.

Known vulnerabilities
38
Active installs
700,000+
Latest version
6.2.15
Last updated
30 Sep 2026
Most recent
1 Oct 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-103343
Medium 6.5Up to 6.2.14Fixed in a later version (latest 6.2.15)6 d ago
Broken access control
CVE-2026-103353
Medium 5.3Up to 6.2.14Fixed in a later version (latest 6.2.15)6 d ago
Cross-site scripting (XSS)
CVE-2026-18146
High 7.2Up to 6.2.11Fixed in a later version (latest 6.2.15)13 Aug 2026
Cross-site scripting (XSS)
CVE-2026-17571
Medium 6.1Up to 6.2.8Fixed in a later version (latest 6.2.15)1 Aug 2026
Broken access control
CVE-2026-17567
Medium 5.3Up to 6.2.8Fixed in a later version (latest 6.2.15)31 Jul 2026
Cross-site scripting (XSS)
CVE-2026-11881
Medium 6.1Before 6.2.6Fixed in 6.2.630 Jul 2026
Cross-site scripting (XSS)
CVE-2026-16655
High 7.2Up to 6.2.7Fixed in a later version (latest 6.2.15)29 Jul 2026
Broken access control
CVE-2026-5069
Medium 5.4Up to 6.2.1Fixed in a later version (latest 6.2.15)10 Jul 2026
Security weakness
CVE-2026-11578
Low 2.7Before 6.2.5Fixed in 6.2.52 Jul 2026
Security weakness
CVE-2026-11880
Low 3.1Before 6.2.1Fixed in 6.2.11 Jul 2026
Broken access control
CVE-2026-5395
High 8.2Up to 6.2.0Fixed in a later version (latest 6.2.15)14 May 2026
Broken access control
CVE-2026-5396
High 8.2Up to 6.1.21Fixed in a later version (latest 6.2.15)14 May 2026
Cross-site scripting (XSS)
CVE-2026-6828
Medium 6.4Up to 6.2.1Fixed in a later version (latest 6.2.15)13 May 2026
Arbitrary file read
CVE-2026-6344
Medium 4.9Up to 6.2.1Fixed in a later version (latest 6.2.15)6 May 2026
Broken access control
CVE-2026-4160
Medium 5.3Up to 6.1.21Fixed in a later version (latest 6.2.15)16 Apr 2026
Cross-site scripting (XSS)
CVE-2026-2365
High 7.2Up to 6.1.17Fixed in a later version (latest 6.2.15)5 Mar 2026
Cross-site scripting (XSS)
CVE-2026-0996
Medium 6.4Up to 6.1.14Fixed in a later version (latest 6.2.15)10 Feb 2026
Broken access control
CVE-2025-13722
Medium 5.3Up to 6.1.7Fixed in a later version (latest 6.2.15)7 Jan 2026
Broken access control
CVE-2025-13748
Medium 5.3Up to 6.1.7Fixed in a later version (latest 6.2.15)6 Dec 2025
Remote code execution
CVE-2025-9260
Medium 6.5Not yet publishedCheck for an update3 Sep 2025
Cross-site scripting (XSS)
CVE-2025-3615
Medium 6.4Up to 6.0.2Fixed in a later version (latest 6.2.15)17 Apr 2025
Security weakness
CVE-2024-13666
Medium 5.3Up to 5.2.12Fixed in a later version (latest 6.2.15)22 Mar 2025
Cross-site scripting (XSS)
CVE-2024-10646
High 7.2Before 5.2.7Fixed in 5.2.714 Dec 2024
Cross-site scripting (XSS)
CVE-2024-9651
Medium 6.1Before 5.2.1Fixed in 5.2.19 Dec 2024
Cross-site scripting (XSS)
CVE-2024-9528
Medium 4.9Before 5.1.20Fixed in 5.1.205 Oct 2024
Broken access control
CVE-2024-5053
Medium 4.2Before 5.1.19Fixed in 5.1.191 Sep 2024
Cross-site scripting (XSS)
CVE-2024-6703
Medium 4.9Before 5.1.20Fixed in 5.1.2027 Jul 2024
Cross-site scripting (XSS)
CVE-2024-6520
Medium 4.4Before 5.1.20Fixed in 5.1.2027 Jul 2024
Cross-site scripting (XSS)
CVE-2024-6521
Medium 4.4Before 5.1.20Fixed in 5.1.2027 Jul 2024
Cross-site scripting (XSS)
CVE-2024-6518
Medium 4.4Before 5.1.20Fixed in 5.1.2027 Jul 2024
PHP object injection
CVE-2024-4157
High 7.5Before 5.1.16Fixed in 5.1.1622 May 2024
Cross-site scripting (XSS)
CVE-2024-4709
Medium 6.4Before 5.1.17Fixed in 5.1.1718 May 2024
Broken access control
CVE-2024-2782
High 7.5Before 5.1.17Fixed in 5.1.1718 May 2024
Privilege escalation
CVE-2024-2771
Critical 9.8Before 5.1.17Fixed in 5.1.1718 May 2024
Cross-site scripting (XSS)
CVE-2023-6957
Medium 4.9Before 5.1.10Fixed in 5.1.1013 Mar 2024
Cross-site scripting (XSS)
CVE-2024-0618
Medium 4.4Up to 5.1.5Fixed in a later version (latest 6.2.15)27 Jan 2024
SQL injection
CVE-2023-24410
Medium 5.5Up to 4.3.25Fixed in a later version (latest 6.2.15)31 Oct 2023
Cross-site scripting (XSS)
CVE-2021-34620
High 8.8Before 3.6.67Fixed in 3.6.677 Jul 2021
Read the published descriptions
CVE-2026-103343, 1 Oct 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP ManageNinja LLC FluentForm fluentform allows Stored XSS.This issue affects FluentForm: from n/a through 6.2.14. CVE record
CVE-2026-103353, 1 Oct 2026
Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14. CVE record
CVE-2026-18146, 13 Aug 2026
The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in the browser of an administrator (or any user with the Fluent Forms entry-viewing capability) when they view the form's entry Submission Logs in the WordPress admin dashboard. Exploitation requires that a site administrator or Fluent Forms manager has configured an email notification whose subject or static (direct) Send To value references an attacker-influenced Smartcode such as an input_password field value, a cookie value, or submission.response. CVE record
CVE-2026-17571, 1 Aug 2026
The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in all versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2026-17567, 31 Jul 2026
The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to brute-force valid transaction hashes and view sensitive payment receipt data including customer name, email address, billing address, order items, payment method, and payment status belonging to other users. Because submission ID, form ID, and transaction creation time are either observable or guessable by an attacker, the effective brute-force space is bounded to approximately 900 candidates per second per (submission, form) pair, making exploitation practical without any prior authentication or account. CVE record
CVE-2026-11881, 30 Jul 2026
The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it. CVE record
CVE-2026-16655, 29 Jul 2026
The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-5069, 10 Jul 2026
The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes it possible for authenticated attackers, with subscriber-level access and above, to submit cancellation requests for other users' subscriptions. CVE record
CVE-2026-11578, 2 Jul 2026
The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default configuration in which an administrator has created at least one Manager restricted to specific forms. CVE record
CVE-2026-11880, 1 Jul 2026
The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users. CVE record
CVE-2026-5395, 14 May 2026
The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Fluent Forms manager-level access and above, to bypass form-level access restrictions to access submissions from forms they are not authorized to view, export data from arbitrary database tables, and enumerate database table names via error message disclosure. CVE record
CVE-2026-5396, 14 May 2026
The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authorizing submission-level actions (read, modify, delete, add notes) based on a user-supplied `form_id` query parameter. This makes it possible for authenticated attackers, with Fluent Forms Manager access restricted to specific forms, to read, modify status, add notes to, and permanently delete form submissions belonging to any other form by spoofing the form_id parameter to a form they are authorized for. CVE record
CVE-2026-6828, 13 May 2026
The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permission_message' parameter in all versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-6344, 6 May 2026
The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attacker-supplied file-upload URLs into filesystem paths without verifying that the resolved path stays inside the WordPress uploads directory: a strpos() prefix check on the raw URL can be bypassed with traversal sequences, wp_normalize_path() does not resolve ".\..\" segments, and file_exists() then resolves them at the kernel level. This makes it possible for authenticated attackers with administrator access to read arbitrary files readable by the web-server user - including wp-config.php with its database credentials and authentication salts - by submitting a form whose admin notification is configured to attach a file-upload field and supplying a crafted URL of the shape <upload_baseurl>/../../<target> as the file-field value. The resolved file is attached to the outbound admin-notification email via wp_mail(). While the email can be triggered by unauthenticated users, the email recipient is not user-controlled. CVE record
CVE-2026-4160, 16 Apr 2026
The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownership validation on a user controlled key in the Stripe SCA confirmation AJAX endpoint. This makes it possible for unauthenticated attackers to modify payment status of targeted pending submissions (for example, setting the status to "failed"). CVE record
CVE-2026-2365, 5 Mar 2026
The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_save_data` AJAX action in all versions up to, and including, 6.1.17. This is due to the draft form submission endpoint being publicly accessible without authentication or nonce verification, combined with insufficient input sanitization and output escaping of form field data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views a partial form entry. CVE record
CVE-2026-0996, 10 Feb 2026
The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all versions up to, and including, 6.1.14 due to a combination of missing authorization checks, a leaked nonce, and insufficient input sanitization. The vulnerability allows Subscriber-level users to trigger AI form generation via a protected endpoint. When prompted, AI services will typically return bare JavaScript code (without <script> tags), which bypasses the plugin's sanitization. This stored JavaScript executes whenever anyone views the generated form, making it possible for authenticated attackers with Subscriber-level access and above to inject arbitrary web scripts that will execute in the context of any user accessing the form. CVE record
CVE-2025-13722, 7 Jan 2026
The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary forms via the publicly exposed AI builder. CVE record
CVE-2025-13748, 6 Dec 2025
The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.1.7 via the 'submission_id' parameter due to missing validation on a user controlled key within the confirmScaPayment() function. This makes it possible for unauthenticated attackers to mark arbitrary submissions as failed via crafted requests to the endpoint granted they can guess or enumerate a valid submission identifier. CVE record
CVE-2025-9260, 3 Sep 2025
The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to read arbitrary files. If allow_url_include is enabled on the server, remote code execution is possible. While the vendor patched this issue in version 6.1.0, the patch caused a fatal error in the vulnerable code, due to a missing class import, so we consider 6.1.2 to be the most complete and best patched version CVE record
CVE-2025-3615, 17 Apr 2025
The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-13666, 22 Mar 2025
The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers spoof their IP address and submit forms that may have IP-based restrictions. CVE record
CVE-2024-10646, 14 Dec 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-9651, 9 Dec 2024
The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-9528, 5 Oct 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form label fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to edit forms (administrator by default), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-5053, 1 Sep 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in all versions up to, and including, 5.1.18. This makes it possible for Form Managers with a Subscriber-level access and above to modify the Mailchimp API key used for integration. At the same time, missing Mailchimp API key validation allows the redirect of the integration requests to the attacker-controlled server. CVE record
CVE-2024-6703, 27 Jul 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ and 'btn_txt' parameters in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for attackers with the Form Manager permissions and Subscriber+ user role, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-6520, 27 Jul 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom error message in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE record
CVE-2024-6521, 27 Jul 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dropdown fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE record
CVE-2024-6518, 27 Jul 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via input fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE record
CVE-2024-4157, 22 May 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the extractDynamicValues function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. Successful exploitation requires the attacker to have "View Form" and "Manage Form" permissions, which must be explicitly set by an administrator. However, this requirement can be bypassed when this vulnerability is chained with CVE-2024-2771. CVE record
CVE-2024-4709, 18 May 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, and access granted by an administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2782, 18 May 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to modify all of the plugin's settings. CVE record
CVE-2024-2771, 18 May 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to grant users with Fluent Form management permissions which gives them access to all of the plugin's settings and features. This also makes it possible for unauthenticated attackers to delete manager accounts. CVE record
CVE-2023-6957, 13 Mar 2024
The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploitation level depends on who is granted the right to create forms by an administrator. This level can be as low as contributor, but by default is admin. CVE record
CVE-2024-0618, 27 Jan 2024
The Contact Form Plugin - Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE record
CVE-2023-24410, 31 Oct 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPManageNinja LLC Contact Form Plugin - Fastest Contact Form Builder Plugin for WordPress by Fluent Forms fluentform allows SQL Injection.This issue affects Contact Form Plugin - Fastest Contact Form Builder Plugin for WordPress by Fluent Forms: from n/a through 4.3.25. CVE record
CVE-2021-34620, 7 Jul 2021
The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions CVE record

What to do if you run Fluent Forms

If you run Fluent Forms, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Fluent Forms vulnerabilities

Free. We email you when a new vulnerability is published for Fluent Forms, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support