Stored Cross-Site Scripting Vulnerability in Fluent Forms by WordPress
CVE-2026-16655
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 July 2026
What is CVE-2026-16655?
The Fluent Forms plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability via the Name Field Nested password Member. This occurs due to inadequate input sanitization and output escaping in all versions up to and including 6.2.7. As a result, unauthorized attackers can exploit this flaw to inject malicious web scripts. These scripts are executed whenever an unsuspecting user accesses compromised pages, potentially leading to data theft, site defacement, or other malicious actions.
Affected Version(s)
Fluent Forms β Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 0 <= 6.2.7