Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values
high
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insufficient input sanitization and output escaping. This makes it possible f...
- CVSS:
- 7.2
- Affected:
- up to 6.2.11
- Fixed in:
- 6.2.12
- Disclosed:
- Aug 12, 2026
CVE-2026-18146 on NVD →
Fluent Forms <= 6.2.4 - Insecure Direct Object Reference to Authenticated (Form Manager+) Cross-Form Submission Entry Deletion
medium
The Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.2.4. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with form manager-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 6.2.4
- Fixed in:
- 6.2.5
- Disclosed:
- Aug 11, 2026
CVE-2026-11578 on NVD →
Fluent Forms <= 6.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Subscription Cancellation
medium
The Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.2.0. This is due to missing ownership validation on the subscription_id parameter in the cancel_subscription AJAX route, allowing any authenticated user to cancel subscriptions tied to forms they...
- CVSS:
- 4.3
- Affected:
- up to 6.2.0
- Fixed in:
- 6.2.1
- Disclosed:
- Aug 10, 2026
CVE-2026-11880 on NVD →
Fluent Forms <= 6.2.8 - Reflected Cross-Site Scripting via 'param'
medium
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in all versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a...
- CVSS:
- 6.1
- Affected:
- up to 6.2.8
- Fixed in:
- 6.2.9
- Disclosed:
- Jul 31, 2026
CVE-2026-17571 on NVD →
Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter
medium
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing validation on a user controlled key. This makes it possible for una...
- CVSS:
- 5.3
- Affected:
- up to 6.2.8
- Fixed in:
- 6.2.9
- Disclosed:
- Jul 30, 2026
CVE-2026-17567 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder < 6.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acce...
- CVSS:
- 6.4
- Affected:
- up to 6.2.6
- Fixed in:
- 6.2.6
- Disclosed:
- Jul 30, 2026
CVE-2026-11881 on NVD →
Fluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member
high
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possi...
- CVSS:
- 7.2
- Affected:
- up to 6.2.7
- Fixed in:
- 6.2.8
- Disclosed:
- Jul 28, 2026
CVE-2026-16655 on NVD →
Fluent Forms <= 6.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id'
medium
The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes it possible for authenticated attackers, with subscribe...
- CVSS:
- 5.4
- Affected:
- up to 6.2.1
- Fixed in:
- 6.2.2
- Disclosed:
- Jul 9, 2026
CVE-2026-5069 on NVD →
Fluent Forms <= 6.2.0 - Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter
high
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to missing validation on a user controlled key. This makes it possible for auth...
- CVSS:
- 8.2
- Affected:
- up to 6.2.0
- Fixed in:
- 6.2.1
- Disclosed:
- May 13, 2026
CVE-2026-5395 on NVD →
Fluent Forms <= 6.1.21 - Authenticated (Subscriber+) Authorization Bypass via 'form_id' Parameter
high
The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authorizing submission-level actions (read, modify, delete, add notes) based on a user-supplied `form_id` query parameter. This...
- CVSS:
- 8.2
- Affected:
- up to 6.1.21
- Fixed in:
- 6.2.0
- Disclosed:
- May 13, 2026
CVE-2026-5396 on NVD →
Fluent Forms <= 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'permission_message' Shortcode Attribute
medium
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permission_message' parameter in all versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping. This makes it possib...
- CVSS:
- 6.4
- Affected:
- up to 6.2.1
- Fixed in:
- 6.2.2
- Disclosed:
- May 12, 2026
CVE-2026-6828 on NVD →
Fluent Forms <= 6.2.1 - Authenticated (Administrator+) Arbitrary File Read via Path Traversal in Email Attachment
medium
The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attacker-supplied file-upload URLs into filesystem paths without verifying that the res...
- CVSS:
- 4.9
- Affected:
- up to 6.2.1
- Fixed in:
- 6.2.2
- Disclosed:
- May 5, 2026
CVE-2026-6344 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification
medium
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownership validation on a user controlled...
- CVSS:
- 5.3
- Affected:
- 6.1.21 – 6.1.21
- Fixed in:
- 6.2.0
- Disclosed:
- Apr 16, 2026
CVE-2026-4160 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] <= 6.1.14 (unfixed)
unknown
[en] Missing Authorization vulnerability in Shahjahan Jewel FluentForm fluentform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentForm: from n/a through <= 6.1.14.
- Affected:
- up to 6.1.14
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25313 on NVD →
Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module
medium
The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all versions up to, and including, 6.1.14 due to a combination of missing authorization checks, a leaked nonce, and insufficient input sanitization. The vulnerability allows Subscriber-level users to tri...
- CVSS:
- 6.4
- Affected:
- up to 6.1.14
- Fixed in:
- 6.1.15
- Disclosed:
- Feb 9, 2026
CVE-2026-0996 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.14 - Missing Authorization
medium
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.1.14. This makes it possible for authenticated attackers, with Subscriber-level acc...
- CVSS:
- 4.3
- Affected:
- up to 6.1.14
- Fixed in:
- 6.1.15
- Disclosed:
- Jan 25, 2026
CVE-2026-25313 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] <= 6.1.11 (unfixed)
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Shahjahan Jewel FluentForm fluentform allows Code Injection.This issue affects FluentForm: from n/a through <= 6.1.11.
- Affected:
- up to 6.1.11
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-69001 on NVD →
FluentForm <= 6.1.11 - Unauthenticated Arbitrary Shortcode Execution
medium
The The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.1.11. This is due to the software allowing users to execute an action that does not properly validate a value before...
- CVSS:
- 6.5
- Affected:
- up to 6.1.11
- Fixed in:
- 6.1.12
- Disclosed:
- Jan 13, 2026
CVE-2025-69001 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.8
unknown
[en] The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX action. This makes it possible for aut...
- Affected:
- up to 6.1.8
- Fixed in:
- 6.1.8
- Disclosed:
- Jan 7, 2026
CVE-2025-13722 on NVD →
Fluent Forms <= 6.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder
medium
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX action. This makes it possible for authenti...
- CVSS:
- 5.3
- Affected:
- up to 6.1.7
- Fixed in:
- 6.1.8
- Disclosed:
- Jan 6, 2026
CVE-2025-13722 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.8
unknown
[en] The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.1.7 via the 'submission_id' parameter due to missing validation on a user controlled key within the confirmScaPay...
- Affected:
- up to 6.1.8
- Fixed in:
- 6.1.8
- Disclosed:
- Dec 6, 2025
CVE-2025-13748 on NVD →
Fluent Forms <= 6.1.7 - Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id
medium
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.1.7 via the 'submission_id' parameter due to missing validation on a user controlled key within the confirmScaPayment(...
- CVSS:
- 5.3
- Affected:
- up to 6.1.7
- Fixed in:
- 6.1.8
- Disclosed:
- Dec 5, 2025
CVE-2025-13748 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read
medium
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes it possible for authenticated attackers, with Subscribe...
- CVSS:
- 6.5
- Affected:
- 5.1.16 – 6.1.1
- Fixed in:
- 6.1.2
- Disclosed:
- Sep 2, 2025
CVE-2025-9260 on NVD →
Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inj...
- CVSS:
- 6.4
- Affected:
- up to 6.0.2
- Fixed in:
- 6.0.3
- Disclosed:
- Apr 16, 2025
CVE-2025-3615 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.0.0
unknown
[en] The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. Thi...
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.0
- Disclosed:
- Mar 22, 2025
CVE-2024-13666 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing
medium
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This mak...
- CVSS:
- 5.3
- Affected:
- up to 5.2.12
- Fixed in:
- 6.0.0
- Disclosed:
- Mar 21, 2025
CVE-2024-13666 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.2.7
unknown
[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping. This makes it possible...
- Affected:
- up to 5.2.7
- Fixed in:
- 5.2.7
- Disclosed:
- Dec 14, 2024
CVE-2024-10646 on NVD →
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject
high
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping. This makes it possible for...
- CVSS:
- 7.2
- Affected:
- up to 5.2.6
- Fixed in:
- 5.2.7
- Disclosed:
- Dec 13, 2024
CVE-2024-10646 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.0.9
unknown
[en] Missing Authorization vulnerability in Contact Form - WPManageNinja LLC FluentForm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentForm: from n/a through 5.0.8.
- Affected:
- up to 5.0.9
- Fixed in:
- 5.0.9
- Disclosed:
- Dec 13, 2024
CVE-2023-41952 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.2.1
unknown
[en] The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 5.2.1
- Fixed in:
- 5.2.1
- Disclosed:
- Dec 9, 2024
CVE-2024-9651 on NVD →
Fluent Forms <= 5.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- CVSS:
- 4.4
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.1
- Disclosed:
- Nov 18, 2024
CVE-2024-9651 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.20
unknown
[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form label fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authe...
- Affected:
- up to 5.1.20
- Fixed in:
- 5.1.20
- Disclosed:
- Oct 5, 2024
CVE-2024-9528 on NVD →
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting
medium
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form label fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authentica...
- CVSS:
- 4.9
- Affected:
- up to 5.1.19
- Fixed in:
- 5.1.20
- Disclosed:
- Oct 4, 2024
CVE-2024-9528 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.19
unknown
[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in all versions up to, and including, 5.1.18. This makes it possible for Form M...
- Affected:
- up to 5.1.19
- Fixed in:
- 5.1.19
- Disclosed:
- Sep 1, 2024
CVE-2024-5053 on NVD →
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification
medium
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in all versions up to, and including, 5.1.18. This makes it possible for Form Manage...
- CVSS:
- 4.2
- Affected:
- up to 5.1.18
- Fixed in:
- 5.1.19
- Disclosed:
- Aug 31, 2024
CVE-2024-5053 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.20
unknown
[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- Affected:
- up to 5.1.20
- Fixed in:
- 5.1.20
- Disclosed:
- Jul 27, 2024
CVE-2024-6520 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.20
unknown
[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- Affected:
- up to 5.1.20
- Fixed in:
- 5.1.20
- Disclosed:
- Jul 27, 2024
CVE-2024-6521 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.20
unknown
[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- Affected:
- up to 5.1.20
- Fixed in:
- 5.1.20
- Disclosed:
- Jul 27, 2024
CVE-2024-6518 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.20
unknown
[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ and 'btn_txt' parameters in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This ma...
- Affected:
- up to 5.1.20
- Fixed in:
- 5.1.20
- Disclosed:
- Jul 27, 2024
CVE-2024-6703 on NVD →
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom error message in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authent...
- CVSS:
- 4.4
- Affected:
- up to 5.1.19
- Fixed in:
- 5.1.20
- Disclosed:
- Jul 26, 2024
CVE-2024-6520 on NVD →
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via input fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...
- CVSS:
- 4.4
- Affected:
- up to 5.1.19
- Fixed in:
- 5.1.20
- Disclosed:
- Jul 26, 2024
CVE-2024-6518 on NVD →
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dropdown fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticate...
- CVSS:
- 4.4
- Affected:
- up to 5.1.19
- Fixed in:
- 5.1.20
- Disclosed:
- Jul 26, 2024
CVE-2024-6521 on NVD →
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Welcome Screen Fields
medium
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ and 'btn_txt' parameters in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes i...
- CVSS:
- 4.9
- Affected:
- up to 5.1.19
- Fixed in:
- 5.1.20
- Disclosed:
- Jul 26, 2024
CVE-2024-6703 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.16
unknown
[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the extractDynamicValues function. This makes it possible for authenticated att...
- Affected:
- up to 5.1.16
- Fixed in:
- 5.1.16
- Disclosed:
- May 22, 2024
CVE-2024-4157 on NVD →
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValues
high
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the extractDynamicValues function. This makes it possible for authenticated attacker...
- CVSS:
- 7.5
- Affected:
- up to 5.1.15
- Fixed in:
- 5.1.16
- Disclosed:
- May 21, 2024
CVE-2024-4157 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.17
unknown
[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping. This makes it possible for aut...
- Affected:
- up to 5.1.17
- Fixed in:
- 5.1.17
- Disclosed:
- May 18, 2024
CVE-2024-4709 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.17
unknown
[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for un...
- Affected:
- up to 5.1.17
- Fixed in:
- 5.1.17
- Disclosed:
- May 18, 2024
CVE-2024-2771 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.17
unknown
[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This make...
- Affected:
- up to 5.1.17
- Fixed in:
- 5.1.17
- Disclosed:
- May 18, 2024
CVE-2024-2782 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.14
unknown
[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 5.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authentic...
- Affected:
- up to 5.1.14
- Fixed in:
- 5.1.14
- Disclosed:
- May 18, 2024
CVE-2024-2772 on NVD →
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 5.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 5.1.13
- Fixed in:
- 5.1.14
- Disclosed:
- May 17, 2024
CVE-2024-2772 on NVD →
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation
high
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This makes it...
- CVSS:
- 7.5
- Affected:
- up to 5.1.16
- Fixed in:
- 5.1.17
- Disclosed:
- May 17, 2024
CVE-2024-2782 on NVD →
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation
critical
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthe...
- CVSS:
- 9.8
- Affected:
- up to 5.1.16
- Fixed in:
- 5.1.17
- Disclosed:
- May 17, 2024
CVE-2024-2771 on NVD →
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping. This makes it possible for authenti...
- CVSS:
- 6.4
- Affected:
- up to 5.1.16
- Fixed in:
- 5.1.17
- Disclosed:
- May 17, 2024
CVE-2024-4709 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.10
unknown
[en] The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will exe...
- Affected:
- up to 5.1.10
- Fixed in:
- 5.1.10
- Disclosed:
- Mar 13, 2024
CVE-2023-6957 on NVD →
Fluent Forms <= 5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute...
- CVSS:
- 4.9
- Affected:
- up to 5.1.9
- Fixed in:
- 5.1.10
- Disclosed:
- Mar 5, 2024
CVE-2023-6957 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.7
unknown
[en] The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for a...
- Affected:
- up to 5.1.7
- Fixed in:
- 5.1.7
- Disclosed:
- Jan 27, 2024
CVE-2024-0618 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.7
unknown
Update the WordPress FluentForm plugin to the latest available version (at least 5.1.7).
Akbar Kustirama discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress FluentForm Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML...
- Affected:
- up to 5.1.7
- Fixed in:
- 5.1.7
- Disclosed:
- Jan 19, 2024
Fluent Forms <= 5.1.5 - Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title
medium
The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authen...
- CVSS:
- 4.4
- Affected:
- up to 5.1.5
- Fixed in:
- 5.1.7
- Disclosed:
- Jan 18, 2024
CVE-2024-0618 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.7
unknown
The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authen...
- Affected:
- up to 5.1.7
- Fixed in:
- 5.1.7
- Disclosed:
- Jan 18, 2024
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.0.0
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPManageNinja LLC Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms fluentform allows SQL Injection.This issue affects Contact Form Plugin – Fastest Contact For...
- Affected:
- up to 5.0.0
- Fixed in:
- 5.0.0
- Disclosed:
- Oct 31, 2023
CVE-2023-24410 on NVD →
Contact Form for Plugin by Fluent Forms <= 5.0.8 - Insecure Direct Object Reference
medium
The Contact Form for Plugin by Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.8 via the addIsRenderableFilter() function due to missing validation on the publication status of a form. This makes it possible for users to render and submit forms w...
- CVSS:
- 5.3
- Affected:
- up to 5.0.9
- Fixed in:
- 5.0.9
- Disclosed:
- Sep 8, 2023
CVE-2023-41952 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.0.9
unknown
The Contact Form for Plugin by Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.8 via the addIsRenderableFilter() function due to missing validation on the publication status of a form. This makes it possible for users to render and submit forms w...
- Affected:
- up to 5.0.9
- Fixed in:
- 5.0.9
- Disclosed:
- Sep 8, 2023
FluentForm <= 4.3.25 - Authenticated (Administrator+) SQL Injection
high
The FluentForm plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.3.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and a...
- CVSS:
- 7.2
- Affected:
- up to 4.3.25
- Fixed in:
- 5.0.0
- Disclosed:
- Jul 12, 2023
CVE-2023-24410 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 4.3.25
unknown
[en] The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with roles as low as contributor to inject arbitrary javascript into a form which will trigger for any visitor to the form or admins...
- Affected:
- up to 4.3.25
- Fixed in:
- 4.3.25
- Disclosed:
- Apr 10, 2023
CVE-2023-0546 on NVD →
FluentForms <= 4.3.24 - Authenticated(Contributor+) Stored Cross-Site Scripting
medium
The FluentForms plugin for WrodPress is vulnerable to stored Cross-Site Scripting via custom form fields in versions up to, and including, 4.3.24. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user...
- CVSS:
- 6.4
- Affected:
- up to 4.3.24
- Fixed in:
- 4.3.25
- Disclosed:
- Mar 20, 2023
CVE-2023-0546 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 4.3.13
unknown
[en] The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
- Affected:
- up to 4.3.13
- Fixed in:
- 4.3.13
- Disclosed:
- Nov 7, 2022
CVE-2022-3463 on NVD →
Contact Form Plugin by FluentForm <= 4.3.12 - CSV Injection
high
The Contact Form Plugin by FluentForm plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 4.3.12. This allows attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable co...
- CVSS:
- 8.3
- Affected:
- up to 4.3.12
- Fixed in:
- 4.3.13
- Disclosed:
- Oct 17, 2022
CVE-2022-3463 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 3.6.67
unknown
[en] The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions
- Affected:
- up to 3.6.67
- Fixed in:
- 3.6.67
- Disclosed:
- Jul 7, 2021
CVE-2021-34620 on NVD →
WP Fluent Forms < 3.6.67 - Stored Cross-Site Scripting
high
The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions
- CVSS:
- 8.8
- Affected:
- up to 3.6.67
- Fixed in:
- 3.6.67
- Disclosed:
- Jun 16, 2021
CVE-2021-34620 on NVD →
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.0.3
unknown
- Affected:
- up to 6.0.3
- Fixed in:
- 6.0.3
CVE-2025-3615 on NVD →