Junglewise Threat Intelligence

CVE-2026-16655: Fluent Forms Stored XSS in Name Field Nested password Member

CVE-2026-16655 · Severity: high · CVSS 7.2 · Published 2026-07-29

Executive brief

Fluent Forms is a popular WordPress plugin used to create contact forms, surveys, and quizzes. A security flaw allows unauthenticated visitors to inject malicious scripts into the website through form fields. These scripts can then execute in the browsers of other users or administrators, potentially leading to unauthorized actions or data theft.

Technical details

The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the Name Field Nested 'password' member. An unauthenticated attacker can exploit this by submitting a specially crafted form entry containing malicious JavaScript. Because the input is stored without proper neutralization, the script will execute in the security context of any user (including administrators) who subsequently views the submission or the page where the data is displayed. This vulnerability is present in all versions up to and including 6.2.7 and has been addressed in version 6.2.8.

Affected products

  • wpmanageninja Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder up to, and including, 6.2.7

Timeline

  • 2026-07-29: disclosed: CVE published by Wordfence and NVD
  • 2026-07-29: advisory
  • 2026-07-29: patched: Version 6.2.8 released to address the issue

References

Related threats