HomeWordPress vulnerabilitiesFluent Forms
Fluent Forms vulnerabilities
Fluent Forms has 38 known vulnerabilities in this database. The most recent published record is dated 1 Oct 2026.
- Known vulnerabilities
- 38
- Active installs
- 700,000+
- Latest version
- 6.2.15
- Last updated
- 30 Sep 2026
- Most recent
- 1 Oct 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-103343 | Medium 6.5 | Up to 6.2.14 | Fixed in a later version (latest 6.2.15) | 6 d ago |
| Broken access control CVE-2026-103353 | Medium 5.3 | Up to 6.2.14 | Fixed in a later version (latest 6.2.15) | 6 d ago |
| Cross-site scripting (XSS) CVE-2026-18146 | High 7.2 | Up to 6.2.11 | Fixed in a later version (latest 6.2.15) | 13 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-17571 | Medium 6.1 | Up to 6.2.8 | Fixed in a later version (latest 6.2.15) | 1 Aug 2026 |
| Broken access control CVE-2026-17567 | Medium 5.3 | Up to 6.2.8 | Fixed in a later version (latest 6.2.15) | 31 Jul 2026 |
| Cross-site scripting (XSS) CVE-2026-11881 | Medium 6.1 | Before 6.2.6 | Fixed in 6.2.6 | 30 Jul 2026 |
| Cross-site scripting (XSS) CVE-2026-16655 | High 7.2 | Up to 6.2.7 | Fixed in a later version (latest 6.2.15) | 29 Jul 2026 |
| Broken access control CVE-2026-5069 | Medium 5.4 | Up to 6.2.1 | Fixed in a later version (latest 6.2.15) | 10 Jul 2026 |
| Security weakness CVE-2026-11578 | Low 2.7 | Before 6.2.5 | Fixed in 6.2.5 | 2 Jul 2026 |
| Security weakness CVE-2026-11880 | Low 3.1 | Before 6.2.1 | Fixed in 6.2.1 | 1 Jul 2026 |
| Broken access control CVE-2026-5395 | High 8.2 | Up to 6.2.0 | Fixed in a later version (latest 6.2.15) | 14 May 2026 |
| Broken access control CVE-2026-5396 | High 8.2 | Up to 6.1.21 | Fixed in a later version (latest 6.2.15) | 14 May 2026 |
| Cross-site scripting (XSS) CVE-2026-6828 | Medium 6.4 | Up to 6.2.1 | Fixed in a later version (latest 6.2.15) | 13 May 2026 |
| Arbitrary file read CVE-2026-6344 | Medium 4.9 | Up to 6.2.1 | Fixed in a later version (latest 6.2.15) | 6 May 2026 |
| Broken access control CVE-2026-4160 | Medium 5.3 | Up to 6.1.21 | Fixed in a later version (latest 6.2.15) | 16 Apr 2026 |
| Cross-site scripting (XSS) CVE-2026-2365 | High 7.2 | Up to 6.1.17 | Fixed in a later version (latest 6.2.15) | 5 Mar 2026 |
| Cross-site scripting (XSS) CVE-2026-0996 | Medium 6.4 | Up to 6.1.14 | Fixed in a later version (latest 6.2.15) | 10 Feb 2026 |
| Broken access control CVE-2025-13722 | Medium 5.3 | Up to 6.1.7 | Fixed in a later version (latest 6.2.15) | 7 Jan 2026 |
| Broken access control CVE-2025-13748 | Medium 5.3 | Up to 6.1.7 | Fixed in a later version (latest 6.2.15) | 6 Dec 2025 |
| Remote code execution CVE-2025-9260 | Medium 6.5 | Not yet published | Check for an update | 3 Sep 2025 |
| Cross-site scripting (XSS) CVE-2025-3615 | Medium 6.4 | Up to 6.0.2 | Fixed in a later version (latest 6.2.15) | 17 Apr 2025 |
| Security weakness CVE-2024-13666 | Medium 5.3 | Up to 5.2.12 | Fixed in a later version (latest 6.2.15) | 22 Mar 2025 |
| Cross-site scripting (XSS) CVE-2024-10646 | High 7.2 | Before 5.2.7 | Fixed in 5.2.7 | 14 Dec 2024 |
| Cross-site scripting (XSS) CVE-2024-9651 | Medium 6.1 | Before 5.2.1 | Fixed in 5.2.1 | 9 Dec 2024 |
| Cross-site scripting (XSS) CVE-2024-9528 | Medium 4.9 | Before 5.1.20 | Fixed in 5.1.20 | 5 Oct 2024 |
| Broken access control CVE-2024-5053 | Medium 4.2 | Before 5.1.19 | Fixed in 5.1.19 | 1 Sep 2024 |
| Cross-site scripting (XSS) CVE-2024-6703 | Medium 4.9 | Before 5.1.20 | Fixed in 5.1.20 | 27 Jul 2024 |
| Cross-site scripting (XSS) CVE-2024-6520 | Medium 4.4 | Before 5.1.20 | Fixed in 5.1.20 | 27 Jul 2024 |
| Cross-site scripting (XSS) CVE-2024-6521 | Medium 4.4 | Before 5.1.20 | Fixed in 5.1.20 | 27 Jul 2024 |
| Cross-site scripting (XSS) CVE-2024-6518 | Medium 4.4 | Before 5.1.20 | Fixed in 5.1.20 | 27 Jul 2024 |
| PHP object injection CVE-2024-4157 | High 7.5 | Before 5.1.16 | Fixed in 5.1.16 | 22 May 2024 |
| Cross-site scripting (XSS) CVE-2024-4709 | Medium 6.4 | Before 5.1.17 | Fixed in 5.1.17 | 18 May 2024 |
| Broken access control CVE-2024-2782 | High 7.5 | Before 5.1.17 | Fixed in 5.1.17 | 18 May 2024 |
| Privilege escalation CVE-2024-2771 | Critical 9.8 | Before 5.1.17 | Fixed in 5.1.17 | 18 May 2024 |
| Cross-site scripting (XSS) CVE-2023-6957 | Medium 4.9 | Before 5.1.10 | Fixed in 5.1.10 | 13 Mar 2024 |
| Cross-site scripting (XSS) CVE-2024-0618 | Medium 4.4 | Up to 5.1.5 | Fixed in a later version (latest 6.2.15) | 27 Jan 2024 |
| SQL injection CVE-2023-24410 | Medium 5.5 | Up to 4.3.25 | Fixed in a later version (latest 6.2.15) | 31 Oct 2023 |
| Cross-site scripting (XSS) CVE-2021-34620 | High 8.8 | Before 3.6.67 | Fixed in 3.6.67 | 7 Jul 2021 |
Read the published descriptions
- CVE-2026-103343, 1 Oct 2026
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP ManageNinja LLC FluentForm fluentform allows Stored XSS.This issue affects FluentForm: from n/a through 6.2.14. CVE record
- CVE-2026-103353, 1 Oct 2026
- Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14. CVE record
- CVE-2026-18146, 13 Aug 2026
- The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in the browser of an administrator (or any user with the Fluent Forms entry-viewing capability) when they view the form's entry Submission Logs in the WordPress admin dashboard. Exploitation requires that a site administrator or Fluent Forms manager has configured an email notification whose subject or static (direct) Send To value references an attacker-influenced Smartcode such as an input_password field value, a cookie value, or submission.response. CVE record
- CVE-2026-17571, 1 Aug 2026
- The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in all versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2026-17567, 31 Jul 2026
- The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to brute-force valid transaction hashes and view sensitive payment receipt data including customer name, email address, billing address, order items, payment method, and payment status belonging to other users. Because submission ID, form ID, and transaction creation time are either observable or guessable by an attacker, the effective brute-force space is bounded to approximately 900 candidates per second per (submission, form) pair, making exploitation practical without any prior authentication or account. CVE record
- CVE-2026-11881, 30 Jul 2026
- The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it. CVE record
- CVE-2026-16655, 29 Jul 2026
- The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-5069, 10 Jul 2026
- The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes it possible for authenticated attackers, with subscriber-level access and above, to submit cancellation requests for other users' subscriptions. CVE record
- CVE-2026-11578, 2 Jul 2026
- The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to the forms a restricted Manager is authorized to manage, allowing a Manager limited to specific forms to permanently delete submission entries belonging to other forms. This requires a non-default configuration in which an administrator has created at least one Manager restricted to specific forms. CVE record
- CVE-2026-11880, 1 Jul 2026
- The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription cancellation request, allowing authenticated users with a low-privilege account to cancel subscriptions belonging to other users. CVE record
- CVE-2026-5395, 14 May 2026
- The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Fluent Forms manager-level access and above, to bypass form-level access restrictions to access submissions from forms they are not authorized to view, export data from arbitrary database tables, and enumerate database table names via error message disclosure. CVE record
- CVE-2026-5396, 14 May 2026
- The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authorizing submission-level actions (read, modify, delete, add notes) based on a user-supplied `form_id` query parameter. This makes it possible for authenticated attackers, with Fluent Forms Manager access restricted to specific forms, to read, modify status, add notes to, and permanently delete form submissions belonging to any other form by spoofing the form_id parameter to a form they are authorized for. CVE record
- CVE-2026-6828, 13 May 2026
- The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permission_message' parameter in all versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-6344, 6 May 2026
- The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attacker-supplied file-upload URLs into filesystem paths without verifying that the resolved path stays inside the WordPress uploads directory: a strpos() prefix check on the raw URL can be bypassed with traversal sequences, wp_normalize_path() does not resolve ".\..\" segments, and file_exists() then resolves them at the kernel level. This makes it possible for authenticated attackers with administrator access to read arbitrary files readable by the web-server user - including wp-config.php with its database credentials and authentication salts - by submitting a form whose admin notification is configured to attach a file-upload field and supplying a crafted URL of the shape <upload_baseurl>/../../<target> as the file-field value. The resolved file is attached to the outbound admin-notification email via wp_mail(). While the email can be triggered by unauthenticated users, the email recipient is not user-controlled. CVE record
- CVE-2026-4160, 16 Apr 2026
- The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownership validation on a user controlled key in the Stripe SCA confirmation AJAX endpoint. This makes it possible for unauthenticated attackers to modify payment status of targeted pending submissions (for example, setting the status to "failed"). CVE record
- CVE-2026-2365, 5 Mar 2026
- The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_save_data` AJAX action in all versions up to, and including, 6.1.17. This is due to the draft form submission endpoint being publicly accessible without authentication or nonce verification, combined with insufficient input sanitization and output escaping of form field data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views a partial form entry. CVE record
- CVE-2026-0996, 10 Feb 2026
- The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all versions up to, and including, 6.1.14 due to a combination of missing authorization checks, a leaked nonce, and insufficient input sanitization. The vulnerability allows Subscriber-level users to trigger AI form generation via a protected endpoint. When prompted, AI services will typically return bare JavaScript code (without <script> tags), which bypasses the plugin's sanitization. This stored JavaScript executes whenever anyone views the generated form, making it possible for authenticated attackers with Subscriber-level access and above to inject arbitrary web scripts that will execute in the context of any user accessing the form. CVE record
- CVE-2025-13722, 7 Jan 2026
- The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary forms via the publicly exposed AI builder. CVE record
- CVE-2025-13748, 6 Dec 2025
- The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.1.7 via the 'submission_id' parameter due to missing validation on a user controlled key within the confirmScaPayment() function. This makes it possible for unauthenticated attackers to mark arbitrary submissions as failed via crafted requests to the endpoint granted they can guess or enumerate a valid submission identifier. CVE record
- CVE-2025-9260, 3 Sep 2025
- The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to read arbitrary files. If allow_url_include is enabled on the server, remote code execution is possible. While the vendor patched this issue in version 6.1.0, the patch caused a fatal error in the vulnerable code, due to a missing class import, so we consider 6.1.2 to be the most complete and best patched version CVE record
- CVE-2025-3615, 17 Apr 2025
- The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-13666, 22 Mar 2025
- The Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers spoof their IP address and submit forms that may have IP-based restrictions. CVE record
- CVE-2024-10646, 14 Dec 2024
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-9651, 9 Dec 2024
- The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-9528, 5 Oct 2024
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form label fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to edit forms (administrator by default), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-5053, 1 Sep 2024
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in all versions up to, and including, 5.1.18. This makes it possible for Form Managers with a Subscriber-level access and above to modify the Mailchimp API key used for integration. At the same time, missing Mailchimp API key validation allows the redirect of the integration requests to the attacker-controlled server. CVE record
- CVE-2024-6703, 27 Jul 2024
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ and 'btn_txt' parameters in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for attackers with the Form Manager permissions and Subscriber+ user role, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-6520, 27 Jul 2024
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom error message in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE record
- CVE-2024-6521, 27 Jul 2024
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dropdown fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE record
- CVE-2024-6518, 27 Jul 2024
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via input fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE record
- CVE-2024-4157, 22 May 2024
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the extractDynamicValues function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. Successful exploitation requires the attacker to have "View Form" and "Manage Form" permissions, which must be explicitly set by an administrator. However, this requirement can be bypassed when this vulnerability is chained with CVE-2024-2771. CVE record
- CVE-2024-4709, 18 May 2024
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, and access granted by an administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-2782, 18 May 2024
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to modify all of the plugin's settings. CVE record
- CVE-2024-2771, 18 May 2024
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to grant users with Fluent Form management permissions which gives them access to all of the plugin's settings and features. This also makes it possible for unauthenticated attackers to delete manager accounts. CVE record
- CVE-2023-6957, 13 Mar 2024
- The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploitation level depends on who is granted the right to create forms by an administrator. This level can be as low as contributor, but by default is admin. CVE record
- CVE-2024-0618, 27 Jan 2024
- The Contact Form Plugin - Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE record
- CVE-2023-24410, 31 Oct 2023
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPManageNinja LLC Contact Form Plugin - Fastest Contact Form Builder Plugin for WordPress by Fluent Forms fluentform allows SQL Injection.This issue affects Contact Form Plugin - Fastest Contact Form Builder Plugin for WordPress by Fluent Forms: from n/a through 4.3.25. CVE record
- CVE-2021-34620, 7 Jul 2021
- The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions CVE record
What to do if you run Fluent Forms
If you run Fluent Forms, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Fluent Forms vulnerabilities
Free. We email you when a new vulnerability is published for Fluent Forms, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.