Junglewise Threat Intelligence

CVE-2026-66633: Fluent Forms Pro Add On Pack unauthenticated cross-site scripting

CVE-2026-66633 · Severity: high · CVSS 7.1 · Published 2026-08-18

Vendors: WP ManageNinja LLC.

Executive brief

Fluent Forms Pro Add On Pack is a popular WordPress plugin for creating and managing web forms. An unauthenticated attacker can inject malicious scripts into the website through this vulnerability, allowing them to steal visitor data, hijack user accounts, or compromise the site's functionality without requiring any special access or credentials.

Technical details

This is an unauthenticated cross-site scripting (XSS) vulnerability in Fluent Forms Pro Add On Pack versions prior to 6.2.12. The vulnerability allows attackers to inject malicious scripts that execute in the context of the affected website. While the vulnerability can be initiated by unauthenticated users, successful exploitation requires user interaction (such as a visitor clicking a malicious link or visiting a crafted page). The injected scripts can steal session cookies, perform actions on behalf of users, or redirect visitors to malicious sites. The patch is available in version 6.2.12 and later.

Affected products

  • WP ManageNinja LLC Fluent Forms Pro Add On Pack < 6.2.12

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: version 6.2.12

References