๐Ÿ” CVE Alert

CVE-2026-11881

MEDIUM 6.1

Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it.

Vendor unknown
Product fluent forms
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown fluent forms

Be the first to know when new medium vulnerabilities affecting unknown fluent forms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Fluent Forms
0 < 6.2.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/3ccc3b34-44ed-4489-86e5-4c0ae800ef73/

Credits

Muni Nitish Kumar Yaddala WPScan