PT-2026-71395 · WordPress · Fluent Forms
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Fluent Forms versions prior to 6.2.12
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server. This occurs via Notification Smartcode Values, enabling the execution of arbitrary web scripts in the browser of an administrator or any user with entry-viewing capabilities when accessing the Submission Logs in the WordPress admin dashboard. Exploitation is possible if an administrator or manager has configured an email notification where the subject or the static Send To value references an attacker-influenced Smartcode, such as
input password, cookie, or submission.response.Recommendations
Update to version 6.2.12 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fluent Forms