Stored Cross-Site Scripting Vulnerability in Fluent Forms by WordPress
CVE-2026-16655

7.2HIGH

What is CVE-2026-16655?

The Fluent Forms plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability via the Name Field Nested password Member. This occurs due to inadequate input sanitization and output escaping in all versions up to and including 6.2.7. As a result, unauthorized attackers can exploit this flaw to inject malicious web scripts. These scripts are executed whenever an unsuspecting user accesses compromised pages, potentially leading to data theft, site defacement, or other malicious actions.

Affected Version(s)

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 0 <= 6.2.7

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo
.