CVE-2026-6344
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
Minimum safe version
6.2.2
Update to 6.2.2 or later to address 33 fixable vulnerabilities
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read
CVE-2026-4160
Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module
CVE-2026-25313
CVE-2025-69001
CVE-2025-13722
CVE-2025-13748
Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2024-13666
CVE-2024-10646
CVE-2024-9651
WordPress FluentForm Plugin <= 5.1.19 is vulnerable to Cross Site Scripting (XSS)
WordPress FluentForm Plugin <= 5.1.18 is vulnerable to Broken Access Control
CVE-2024-6521
CVE-2024-6518
CVE-2024-6703
WordPress FluentForm Plugin <= 5.1.19 is vulnerable to Cross Site Scripting (XSS)
WordPress FluentForm Plugin <= 5.1.15 is vulnerable to PHP Object Injection
WordPress FluentForm Plugin <= 5.1.16 is vulnerable to Cross Site Scripting (XSS)
WordPress FluentForm Plugin <= 5.1.13 is vulnerable to Cross Site Scripting (XSS)
WordPress FluentForm Plugin <= 5.1.16 is vulnerable to Privilege Escalation
WordPress FluentForm Plugin <= 5.1.16 is vulnerable to Broken Access Control
CVE-2023-6957
CVE-2024-0618
WordPress FluentForm Plugin <= 5.1.5 is vulnerable to Cross Site Scripting (XSS)
Fluent Forms <= 5.1.5 - Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title
CVE-2023-41952
Contact Form for Plugin by Fluent Forms <= 5.0.8 - Insecure Direct Object Reference
CVE-2023-24410
WordPress FluentForm Plugin < 4.3.25 is vulnerable to Cross Site Scripting (XSS)
CVE-2022-3463
CVE-2021-34620