WordPress · Fluent Forms · CVE-2026-18146
**Name of the Vulnerable Software and Affected Versions**
Fluent Forms versions prior to 6.2.12
**Description**
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server. This occurs via Notification Smartcode Values, enabling the execution of arbitrary web scripts in the browser of an administrator or any user with entry-viewing capabilities when accessing the Submission Logs in the WordPress admin dashboard. Exploitation is possible if an administrator or manager has configured an email notification where the subject or the static Send To value references an attacker-influenced Smartcode, such as `input password`, `cookie`, or `submission.response`.
**Recommendations**
Update to version 6.2.12 or later.