Stored Cross-Site Scripting Risk in Fluent Forms Pro Plugin for WordPress
CVE-2026-2365

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 March 2026

What is CVE-2026-2365?

The Fluent Forms Pro plugin for WordPress contains a vulnerability that exposes the fluentform_step_form_save_data AJAX action. This exposure enables unauthenticated attackers to execute stored cross-site scripting attacks by injecting arbitrary web scripts through the publicly accessible draft form submission endpoint, which lacks proper authentication and nonce verification. Furthermore, insufficient input sanitization and output escaping of form field data increase the risk, allowing malicious scripts to execute whenever an administrator views a partial form entry.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Fluent Forms Pro Add On Pack * <= 6.1.17

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Prickly Cactus
.