CVE-2026-11881
Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it.
| Vendor | unknown |
| Product | fluent forms |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown fluent forms
Be the first to know when new medium vulnerabilities affecting unknown fluent forms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Fluent Forms
0 < 6.2.6
References
Credits
Muni Nitish Kumar Yaddala WPScan