Stored Cross-Site Scripting in Fluent Forms Contact Form Builder Plugin for WordPress
CVE-2026-18146

7.2HIGH

What is CVE-2026-18146?

The Fluent Forms plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability stemming from inadequate input sanitization and output escaping. This flaw can be exploited by unauthenticated attackers through crafted Smartcode values in email notifications, allowing them to inject malicious scripts that execute in the browsers of administrators or users with access to the form submission logs. Attackers can leverage this vulnerability by manipulating inputs such as password fields or cookie values in configurations that reference them within the WordPress admin area.

Affected Version(s)

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 0 <= 6.2.11

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrien Brunner
.