Cross-Site Scripting
18 records48.6%First: 2021. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 37 vulnerability records associated with Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder, published between 2021 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2021 | 1 | |
| 2022 | 1 | |
| 2023 | 3 | |
| 2024 | 15 | |
| 2025 | 4 | |
| 2026 | 13 |
| Severity | Records | Share |
|---|---|---|
| Critical | 1 | 2.7% |
| High | 9 | 24.3% |
| Medium | 27 | 73% |
First: 2021. Latest: 2026.
First: 2023. Latest: 2026.
First: 2022. Latest: 2026.
First: 2023. Latest: 2023.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
6.2.96.2.86.2.16.2.26.2.06.1.156.1.126.1.86.1.26.0.36.0.05.2.75.2.15.1.195.1.205.1.165.1.145.1.175.1.105.1.75.0.95.0.04.3.254.3.133.6.67Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-6.2.8 | Fluent Forms <= 6.2.8 - Reflected Cross-Site Scripting via 'param' | July 31, 2026 | 6.2.9 | Medium |
*-6.2.8 | Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter | July 30, 2026 | 6.2.9 | Medium |
*-6.2.7 | Fluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member | July 28, 2026 | 6.2.8 | High |
*-6.2.1 | Fluent Forms <= 6.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id' | July 9, 2026 | 6.2.2 | Medium |
*-6.2.0 | Fluent Forms <= 6.2.0 - Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter | May 13, 2026 | 6.2.1 | High |
*-6.1.21 | Fluent Forms <= 6.1.21 - Authenticated (Subscriber+) Authorization Bypass via 'form_id' Parameter | May 13, 2026 | 6.2.0 | High |
*-6.2.1 | Fluent Forms <= 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'permission_message' Shortcode Attribute | May 12, 2026 | 6.2.2 | Medium |
*-6.2.1 | Fluent Forms <= 6.2.1 - Authenticated (Administrator+) Arbitrary File Read via Path Traversal in Email Attachment | May 5, 2026 | 6.2.2 | Medium |
6.1.21 | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification | April 16, 2026 | 6.2.0 | Medium |
*-6.1.14 | Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module | February 9, 2026 | 6.1.15 | Medium |
*-6.1.14 | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.14 - Missing Authorization | January 25, 2026 | 6.1.15 | Medium |
*-6.1.11 | FluentForm <= 6.1.11 - Unauthenticated Arbitrary Shortcode Execution | January 13, 2026 | 6.1.12 | Medium |
*-6.1.7 | Fluent Forms <= 6.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder | January 6, 2026 | 6.1.8 | Medium |
*-6.1.7 | Fluent Forms <= 6.1.7 - Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id | December 5, 2025 | 6.1.8 | Medium |
5.1.16-6.1.1 | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read | September 2, 2025 | 6.1.2 | Medium |
*-6.0.2 | Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | April 16, 2025 | 6.0.3 | Medium |
*-5.2.12 | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing | March 21, 2025 | 6.0.0 | Medium |
*-5.2.6 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject | December 13, 2024 | 5.2.7 | High |
*-5.2.0 | Fluent Forms <= 5.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting | November 18, 2024 | 5.2.1 | Medium |
*-5.1.19 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting | October 4, 2024 | 5.1.20 | Medium |
*-5.1.18 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification | August 31, 2024 | 5.1.19 | Medium |
*-5.1.19 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting | July 26, 2024 | 5.1.20 | Medium |
*-5.1.19 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting | July 26, 2024 | 5.1.20 | Medium |
*-5.1.19 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting | July 26, 2024 | 5.1.20 | Medium |
*-5.1.19 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Welcome Screen Fields | July 26, 2024 | 5.1.20 | Medium |
Selected source records
Published: July 31, 2026
Published: July 30, 2026
Published: July 28, 2026
Published: July 9, 2026
Published: May 13, 2026
Published: May 13, 2026
Published: May 12, 2026
Published: May 5, 2026
Published: May 17, 2024
Published: June 16, 2021
Published: October 17, 2022
Published: May 13, 2026
Published: May 13, 2026
Published: May 17, 2024
Published: May 21, 2024
Published: December 13, 2024
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.