SecAlerts
F

Fluent Forms

Security Risk Profile

48
/100
medium

Security Risk Score

Comprehensive risk assessment based on 24 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 13, 2024 to present

24
Total CVEs
10
Critical+High
0
Exploited
7
Unpatched

Threat Assessment

Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
7
Critical/High
Risk Level
48/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
2
High
8
Medium
12
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
7

Age Distribution

Common Weaknesses (CWE)

1
XSS
13
2
Input Validation
1

Most Affected Products

1. FluentForms Contact Form Wordpress10
2. Fluent Forms Contact Form Plugin5
3. Fluent Forms Fluent Forms4
4. Fluent Forms Fluent Forms Pro Add On Pack3
5. Fluent Forms WordPress plugin3

Recent Vulnerabilities

See more →
CVE-2026-94675
CVSS 7.1high

WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.13 - Cross Site Scripting (XSS) vulnerability

Oct 6, 2026🔧 No Patch
CVE-2026-81297
CVSS 7.5high

WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.12 - Privilege Escalation vulnerability

Aug 31, 2026🔧 No Patch
CVE-2026-73532
CVSS 9.3critical

Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build

Aug 13, 2026🔧 No Patch
CVE-2026-18146
CVSS 7.2high

Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values

Aug 13, 2026🔧 No Patch
CVE-2026-17571
CVSS 6.1medium

Fluent Forms <= 6.2.8 - Reflected Cross-Site Scripting via 'param'

Aug 1, 2026🔧 No Patch
CVE-2026-17567
CVSS 5.3medium

Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter

Jul 31, 2026🔧 No Patch
CVE-2026-11881
CVSS 6.1medium

Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field

Jul 30, 2026🔧 No Patch
CVE-2026-16655
CVSS 7.2high

Fluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member

Jul 29, 2026🔧 No Patch
CVE-2026-15962
CVSS 8.8high

Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field

Jul 26, 2026🔧 No Patch
CVE-2026-11578
CVSS 2.7low

Fluent Forms < 6.2.5 - Form Manager+ Cross-Form Submission Entry Deletion via IDOR

Jul 2, 2026🔧 No Patch

Monitor Fluent Forms in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Fluent Forms Security Vulnerabilities & Risk Score | 24 CVEs | SecAlerts - SecAlerts