Executive brief
Fluent Forms is a popular WordPress plugin used to create contact forms, surveys, and quizzes. A security flaw allows users with contributor-level access or higher to inject malicious scripts into form settings. These scripts will run automatically in the browser of any user who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'permission_message' parameter. This vulnerability exists in all versions up to and including 6.2.1. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into the database. These scripts are then executed in the context of a user's browser whenever they visit the page where the malicious payload is rendered. This could allow for session hijacking or unauthorized administrative actions if a high-privileged user views the page.
Affected products
- WPManageNinja Fluent Forms up to, and including, 6.2.1
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory
References
- https://plugins.trac.wordpress.org/browser/fluentform/tags/6.1.20/app/Modules/Component/Component.php
- https://plugins.trac.wordpress.org/browser/fluentform/tags/6.1.20/app/Modules/Component/Component.php
- https://plugins.trac.wordpress.org/browser/fluentform/trunk/app/Modules/Component/Component.php
- https://plugins.trac.wordpress.org/browser/fluentform/trunk/app/Modules/Component/Component.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3513845%40fluentform&new=3513845%40fluentform&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ce2d2594-e856-4249-9467-01c0fe1c0c71?source=cve