plugin

Fluentform Vulnerabilities

70 known security issues reported for the Fluentform WordPress plugin. Most recent disclosed Aug 12, 2026.

1 critical 10 high 30 medium

Running Fluentform on your site? Check whether your installed version is affected.

Scan your site free

Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values

high

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insufficient input sanitization and output escaping. This makes it possible f...

CVSS:
7.2
Affected:
up to 6.2.11
Fixed in:
6.2.12
Disclosed:
Aug 12, 2026

CVE-2026-18146 on NVD →

Fluent Forms <= 6.2.4 - Insecure Direct Object Reference to Authenticated (Form Manager+) Cross-Form Submission Entry Deletion

medium

The Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.2.4. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with form manager-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 6.2.4
Fixed in:
6.2.5
Disclosed:
Aug 11, 2026

CVE-2026-11578 on NVD →

Fluent Forms <= 6.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Subscription Cancellation

medium

The Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.2.0. This is due to missing ownership validation on the subscription_id parameter in the cancel_subscription AJAX route, allowing any authenticated user to cancel subscriptions tied to forms they...

CVSS:
4.3
Affected:
up to 6.2.0
Fixed in:
6.2.1
Disclosed:
Aug 10, 2026

CVE-2026-11880 on NVD →

Fluent Forms <= 6.2.8 - Reflected Cross-Site Scripting via 'param'

medium

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in all versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a...

CVSS:
6.1
Affected:
up to 6.2.8
Fixed in:
6.2.9
Disclosed:
Jul 31, 2026

CVE-2026-17571 on NVD →

Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter

medium

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missing validation on a user controlled key. This makes it possible for una...

CVSS:
5.3
Affected:
up to 6.2.8
Fixed in:
6.2.9
Disclosed:
Jul 30, 2026

CVE-2026-17567 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder < 6.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 6.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acce...

CVSS:
6.4
Affected:
up to 6.2.6
Fixed in:
6.2.6
Disclosed:
Jul 30, 2026

CVE-2026-11881 on NVD →

Fluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member

high

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possi...

CVSS:
7.2
Affected:
up to 6.2.7
Fixed in:
6.2.8
Disclosed:
Jul 28, 2026

CVE-2026-16655 on NVD →

Fluent Forms <= 6.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id'

medium

The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes it possible for authenticated attackers, with subscribe...

CVSS:
5.4
Affected:
up to 6.2.1
Fixed in:
6.2.2
Disclosed:
Jul 9, 2026

CVE-2026-5069 on NVD →

Fluent Forms <= 6.2.0 - Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter

high

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to missing validation on a user controlled key. This makes it possible for auth...

CVSS:
8.2
Affected:
up to 6.2.0
Fixed in:
6.2.1
Disclosed:
May 13, 2026

CVE-2026-5395 on NVD →

Fluent Forms <= 6.1.21 - Authenticated (Subscriber+) Authorization Bypass via 'form_id' Parameter

high

The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authorizing submission-level actions (read, modify, delete, add notes) based on a user-supplied `form_id` query parameter. This...

CVSS:
8.2
Affected:
up to 6.1.21
Fixed in:
6.2.0
Disclosed:
May 13, 2026

CVE-2026-5396 on NVD →

Fluent Forms <= 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'permission_message' Shortcode Attribute

medium

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permission_message' parameter in all versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping. This makes it possib...

CVSS:
6.4
Affected:
up to 6.2.1
Fixed in:
6.2.2
Disclosed:
May 12, 2026

CVE-2026-6828 on NVD →

Fluent Forms <= 6.2.1 - Authenticated (Administrator+) Arbitrary File Read via Path Traversal in Email Attachment

medium

The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attacker-supplied file-upload URLs into filesystem paths without verifying that the res...

CVSS:
4.9
Affected:
up to 6.2.1
Fixed in:
6.2.2
Disclosed:
May 5, 2026

CVE-2026-6344 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification

medium

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and ownership validation on a user controlled...

CVSS:
5.3
Affected:
6.1.21 – 6.1.21
Fixed in:
6.2.0
Disclosed:
Apr 16, 2026

CVE-2026-4160 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] <= 6.1.14 (unfixed)

unknown

[en] Missing Authorization vulnerability in Shahjahan Jewel FluentForm fluentform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentForm: from n/a through <= 6.1.14.

Affected:
up to 6.1.14
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25313 on NVD →

Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module

medium

The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all versions up to, and including, 6.1.14 due to a combination of missing authorization checks, a leaked nonce, and insufficient input sanitization. The vulnerability allows Subscriber-level users to tri...

CVSS:
6.4
Affected:
up to 6.1.14
Fixed in:
6.1.15
Disclosed:
Feb 9, 2026

CVE-2026-0996 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.14 - Missing Authorization

medium

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.1.14. This makes it possible for authenticated attackers, with Subscriber-level acc...

CVSS:
4.3
Affected:
up to 6.1.14
Fixed in:
6.1.15
Disclosed:
Jan 25, 2026

CVE-2026-25313 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] <= 6.1.11 (unfixed)

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Shahjahan Jewel FluentForm fluentform allows Code Injection.This issue affects FluentForm: from n/a through <= 6.1.11.

Affected:
up to 6.1.11
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-69001 on NVD →

FluentForm <= 6.1.11 - Unauthenticated Arbitrary Shortcode Execution

medium

The The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.1.11. This is due to the software allowing users to execute an action that does not properly validate a value before...

CVSS:
6.5
Affected:
up to 6.1.11
Fixed in:
6.1.12
Disclosed:
Jan 13, 2026

CVE-2025-69001 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 6.1.8

unknown

[en] The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX action. This makes it possible for aut...

Affected:
up to 6.1.8
Fixed in:
6.1.8
Disclosed:
Jan 7, 2026

CVE-2025-13722 on NVD →

Fluent Forms <= 6.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder

medium

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX action. This makes it possible for authenti...

CVSS:
5.3
Affected:
up to 6.1.7
Fixed in:
6.1.8
Disclosed:
Jan 6, 2026

CVE-2025-13722 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 6.1.8

unknown

[en] The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.1.7 via the 'submission_id' parameter due to missing validation on a user controlled key within the confirmScaPay...

Affected:
up to 6.1.8
Fixed in:
6.1.8
Disclosed:
Dec 6, 2025

CVE-2025-13748 on NVD →

Fluent Forms <= 6.1.7 - Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id

medium

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.1.7 via the 'submission_id' parameter due to missing validation on a user controlled key within the confirmScaPayment(...

CVSS:
5.3
Affected:
up to 6.1.7
Fixed in:
6.1.8
Disclosed:
Dec 5, 2025

CVE-2025-13748 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read

medium

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes it possible for authenticated attackers, with Subscribe...

CVSS:
6.5
Affected:
5.1.16 – 6.1.1
Fixed in:
6.1.2
Disclosed:
Sep 2, 2025

CVE-2025-9260 on NVD →

Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inj...

CVSS:
6.4
Affected:
up to 6.0.2
Fixed in:
6.0.3
Disclosed:
Apr 16, 2025

CVE-2025-3615 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 6.0.0

unknown

[en] The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. Thi...

Affected:
up to 6.0.0
Fixed in:
6.0.0
Disclosed:
Mar 22, 2025

CVE-2024-13666 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing

medium

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This mak...

CVSS:
5.3
Affected:
up to 5.2.12
Fixed in:
6.0.0
Disclosed:
Mar 21, 2025

CVE-2024-13666 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.2.7

unknown

[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping. This makes it possible...

Affected:
up to 5.2.7
Fixed in:
5.2.7
Disclosed:
Dec 14, 2024

CVE-2024-10646 on NVD →

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject

high

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping. This makes it possible for...

CVSS:
7.2
Affected:
up to 5.2.6
Fixed in:
5.2.7
Disclosed:
Dec 13, 2024

CVE-2024-10646 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.0.9

unknown

[en] Missing Authorization vulnerability in Contact Form - WPManageNinja LLC FluentForm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentForm: from n/a through 5.0.8.

Affected:
up to 5.0.9
Fixed in:
5.0.9
Disclosed:
Dec 13, 2024

CVE-2023-41952 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.2.1

unknown

[en] The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 5.2.1
Fixed in:
5.2.1
Disclosed:
Dec 9, 2024

CVE-2024-9651 on NVD →

Fluent Forms <= 5.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

CVSS:
4.4
Affected:
up to 5.2.0
Fixed in:
5.2.1
Disclosed:
Nov 18, 2024

CVE-2024-9651 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.20

unknown

[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form label fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authe...

Affected:
up to 5.1.20
Fixed in:
5.1.20
Disclosed:
Oct 5, 2024

CVE-2024-9528 on NVD →

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting

medium

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form label fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authentica...

CVSS:
4.9
Affected:
up to 5.1.19
Fixed in:
5.1.20
Disclosed:
Oct 4, 2024

CVE-2024-9528 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.19

unknown

[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in all versions up to, and including, 5.1.18. This makes it possible for Form M...

Affected:
up to 5.1.19
Fixed in:
5.1.19
Disclosed:
Sep 1, 2024

CVE-2024-5053 on NVD →

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification

medium

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in all versions up to, and including, 5.1.18. This makes it possible for Form Manage...

CVSS:
4.2
Affected:
up to 5.1.18
Fixed in:
5.1.19
Disclosed:
Aug 31, 2024

CVE-2024-5053 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.20

unknown

[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Affected:
up to 5.1.20
Fixed in:
5.1.20
Disclosed:
Jul 27, 2024

CVE-2024-6520 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.20

unknown

[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Affected:
up to 5.1.20
Fixed in:
5.1.20
Disclosed:
Jul 27, 2024

CVE-2024-6521 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.20

unknown

[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Affected:
up to 5.1.20
Fixed in:
5.1.20
Disclosed:
Jul 27, 2024

CVE-2024-6518 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.20

unknown

[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ and 'btn_txt' parameters in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This ma...

Affected:
up to 5.1.20
Fixed in:
5.1.20
Disclosed:
Jul 27, 2024

CVE-2024-6703 on NVD →

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom error message in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authent...

CVSS:
4.4
Affected:
up to 5.1.19
Fixed in:
5.1.20
Disclosed:
Jul 26, 2024

CVE-2024-6520 on NVD →

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via input fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...

CVSS:
4.4
Affected:
up to 5.1.19
Fixed in:
5.1.20
Disclosed:
Jul 26, 2024

CVE-2024-6518 on NVD →

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dropdown fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticate...

CVSS:
4.4
Affected:
up to 5.1.19
Fixed in:
5.1.20
Disclosed:
Jul 26, 2024

CVE-2024-6521 on NVD →

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Welcome Screen Fields

medium

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ and 'btn_txt' parameters in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes i...

CVSS:
4.9
Affected:
up to 5.1.19
Fixed in:
5.1.20
Disclosed:
Jul 26, 2024

CVE-2024-6703 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.16

unknown

[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the extractDynamicValues function. This makes it possible for authenticated att...

Affected:
up to 5.1.16
Fixed in:
5.1.16
Disclosed:
May 22, 2024

CVE-2024-4157 on NVD →

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValues

high

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the extractDynamicValues function. This makes it possible for authenticated attacker...

CVSS:
7.5
Affected:
up to 5.1.15
Fixed in:
5.1.16
Disclosed:
May 21, 2024

CVE-2024-4157 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.17

unknown

[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping. This makes it possible for aut...

Affected:
up to 5.1.17
Fixed in:
5.1.17
Disclosed:
May 18, 2024

CVE-2024-4709 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.17

unknown

[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for un...

Affected:
up to 5.1.17
Fixed in:
5.1.17
Disclosed:
May 18, 2024

CVE-2024-2771 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.17

unknown

[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This make...

Affected:
up to 5.1.17
Fixed in:
5.1.17
Disclosed:
May 18, 2024

CVE-2024-2782 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.14

unknown

[en] The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 5.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authentic...

Affected:
up to 5.1.14
Fixed in:
5.1.14
Disclosed:
May 18, 2024

CVE-2024-2772 on NVD →

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 5.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 5.1.13
Fixed in:
5.1.14
Disclosed:
May 17, 2024

CVE-2024-2772 on NVD →

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation

high

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This makes it...

CVSS:
7.5
Affected:
up to 5.1.16
Fixed in:
5.1.17
Disclosed:
May 17, 2024

CVE-2024-2782 on NVD →

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation

critical

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthe...

CVSS:
9.8
Affected:
up to 5.1.16
Fixed in:
5.1.17
Disclosed:
May 17, 2024

CVE-2024-2771 on NVD →

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping. This makes it possible for authenti...

CVSS:
6.4
Affected:
up to 5.1.16
Fixed in:
5.1.17
Disclosed:
May 17, 2024

CVE-2024-4709 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.10

unknown

[en] The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will exe...

Affected:
up to 5.1.10
Fixed in:
5.1.10
Disclosed:
Mar 13, 2024

CVE-2023-6957 on NVD →

Fluent Forms <= 5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute...

CVSS:
4.9
Affected:
up to 5.1.9
Fixed in:
5.1.10
Disclosed:
Mar 5, 2024

CVE-2023-6957 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.7

unknown

[en] The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for a...

Affected:
up to 5.1.7
Fixed in:
5.1.7
Disclosed:
Jan 27, 2024

CVE-2024-0618 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.7

unknown

Update the WordPress FluentForm plugin to the latest available version (at least 5.1.7). Akbar Kustirama discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress FluentForm Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML...

Affected:
up to 5.1.7
Fixed in:
5.1.7
Disclosed:
Jan 19, 2024

Fluent Forms <= 5.1.5 - Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title

medium

The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authen...

CVSS:
4.4
Affected:
up to 5.1.5
Fixed in:
5.1.7
Disclosed:
Jan 18, 2024

CVE-2024-0618 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.1.7

unknown

The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authen...

Affected:
up to 5.1.7
Fixed in:
5.1.7
Disclosed:
Jan 18, 2024

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.0.0

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPManageNinja LLC Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms fluentform allows SQL Injection.This issue affects Contact Form Plugin – Fastest Contact For...

Affected:
up to 5.0.0
Fixed in:
5.0.0
Disclosed:
Oct 31, 2023

CVE-2023-24410 on NVD →

Contact Form for Plugin by Fluent Forms <= 5.0.8 - Insecure Direct Object Reference

medium

The Contact Form for Plugin by Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.8 via the addIsRenderableFilter() function due to missing validation on the publication status of a form. This makes it possible for users to render and submit forms w...

CVSS:
5.3
Affected:
up to 5.0.9
Fixed in:
5.0.9
Disclosed:
Sep 8, 2023

CVE-2023-41952 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 5.0.9

unknown

The Contact Form for Plugin by Fluent Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.8 via the addIsRenderableFilter() function due to missing validation on the publication status of a form. This makes it possible for users to render and submit forms w...

Affected:
up to 5.0.9
Fixed in:
5.0.9
Disclosed:
Sep 8, 2023

FluentForm <= 4.3.25 - Authenticated (Administrator+) SQL Injection

high

The FluentForm plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.3.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and a...

CVSS:
7.2
Affected:
up to 4.3.25
Fixed in:
5.0.0
Disclosed:
Jul 12, 2023

CVE-2023-24410 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 4.3.25

unknown

[en] The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with roles as low as contributor to inject arbitrary javascript into a form which will trigger for any visitor to the form or admins...

Affected:
up to 4.3.25
Fixed in:
4.3.25
Disclosed:
Apr 10, 2023

CVE-2023-0546 on NVD →

FluentForms <= 4.3.24 - Authenticated(Contributor+) Stored Cross-Site Scripting

medium

The FluentForms plugin for WrodPress is vulnerable to stored Cross-Site Scripting via custom form fields in versions up to, and including, 4.3.24. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user...

CVSS:
6.4
Affected:
up to 4.3.24
Fixed in:
4.3.25
Disclosed:
Mar 20, 2023

CVE-2023-0546 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 4.3.13

unknown

[en] The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection

Affected:
up to 4.3.13
Fixed in:
4.3.13
Disclosed:
Nov 7, 2022

CVE-2022-3463 on NVD →

Contact Form Plugin by FluentForm <= 4.3.12 - CSV Injection

high

The Contact Form Plugin by FluentForm plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 4.3.12. This allows attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable co...

CVSS:
8.3
Affected:
up to 4.3.12
Fixed in:
4.3.13
Disclosed:
Oct 17, 2022

CVE-2022-3463 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 3.6.67

unknown

[en] The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions

Affected:
up to 3.6.67
Fixed in:
3.6.67
Disclosed:
Jul 7, 2021

CVE-2021-34620 on NVD →

WP Fluent Forms < 3.6.67 - Stored Cross-Site Scripting

high

The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions

CVSS:
8.8
Affected:
up to 3.6.67
Fixed in:
3.6.67
Disclosed:
Jun 16, 2021

CVE-2021-34620 on NVD →

Fluent Forms – Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder [fluentform] < 6.0.3

unknown
Affected:
up to 6.0.3
Fixed in:
6.0.3

CVE-2025-3615 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database