PT-2026-71395 · WordPress · Fluent Forms

·

CVE-2026-18146

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fluent Forms versions prior to 6.2.12
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server. This occurs via Notification Smartcode Values, enabling the execution of arbitrary web scripts in the browser of an administrator or any user with entry-viewing capabilities when accessing the Submission Logs in the WordPress admin dashboard. Exploitation is possible if an administrator or manager has configured an email notification where the subject or the static Send To value references an attacker-influenced Smartcode, such as input password, cookie, or submission.response.
Recommendations Update to version 6.2.12 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18146

Affected Products

Fluent Forms