Cross-Site Scripting
18 records48.6%First: 2021. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 37 vulnerability records associated with Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder, published between 2021 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2021 | 1 | |
| 2022 | 1 | |
| 2023 | 3 | |
| 2024 | 15 | |
| 2025 | 4 | |
| 2026 | 13 |
| Severity | Records | Share |
|---|---|---|
| Critical | 1 | 2.7% |
| High | 9 | 24.3% |
| Medium | 27 | 73% |
First: 2021. Latest: 2026.
First: 2023. Latest: 2026.
First: 2022. Latest: 2026.
First: 2023. Latest: 2023.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
6.2.96.2.86.2.16.2.26.2.06.1.156.1.126.1.86.1.26.0.36.0.05.2.75.2.15.1.195.1.205.1.165.1.145.1.175.1.105.1.75.0.95.0.04.3.254.3.133.6.67Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-5.1.15 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValues | May 21, 2024 | 5.1.16 | High |
*-5.1.13 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting | May 17, 2024 | 5.1.14 | Medium |
*-5.1.16 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation | May 17, 2024 | 5.1.17 | High |
*-5.1.16 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation | May 17, 2024 | 5.1.17 | Critical |
*-5.1.16 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting | May 17, 2024 | 5.1.17 | Medium |
*-5.1.9 | Fluent Forms <= 5.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting | March 5, 2024 | 5.1.10 | Medium |
*-5.1.5 | Fluent Forms <= 5.1.5 - Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title | January 18, 2024 | 5.1.7 | Medium |
[*, 5.0.9) | Contact Form for Plugin by Fluent Forms <= 5.0.8 - Insecure Direct Object Reference | September 8, 2023 | 5.0.9 | Medium |
*-4.3.25 | FluentForm <= 4.3.25 - Authenticated (Administrator+) SQL Injection | July 12, 2023 | 5.0.0 | High |
*-4.3.24 | FluentForms <= 4.3.24 - Authenticated(Contributor+) Stored Cross-Site Scripting | March 20, 2023 | 4.3.25 | Medium |
*-4.3.12 | Contact Form Plugin by FluentForm <= 4.3.12 - CSV Injection | October 17, 2022 | 4.3.13 | High |
[*, 3.6.67) | WP Fluent Forms < 3.6.67 - Stored Cross-Site Scripting | June 16, 2021 | 3.6.67 | High |
Selected source records
Published: July 31, 2026
Published: July 30, 2026
Published: July 28, 2026
Published: July 9, 2026
Published: May 13, 2026
Published: May 13, 2026
Published: May 12, 2026
Published: May 5, 2026
Published: May 17, 2024
Published: June 16, 2021
Published: October 17, 2022
Published: May 13, 2026
Published: May 13, 2026
Published: May 17, 2024
Published: May 21, 2024
Published: December 13, 2024
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.