SecAlerts
f

fluentforms

Security Risk Profile

33
/100
low

Security Risk Score

Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from July 7, 2021 to present

19
Total CVEs
7
Critical+High
0
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
33/100
low

Severity Distribution

Critical
3
High
4
Medium
12
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
9

Age Distribution

Common Weaknesses (CWE)

1
XSS
13
2
SQL Injection
1
3
CSRF
1

Most Affected Products

1. FluentForms Contact Form Wordpress18
2. Fluent Forms Contact Form Plugin5
3. Fluent Forms Contact Form Plugin for Quiz, Survey, and Drag & Drop WP Form Builder2
4. Fluent Forms Contact Form Plugin for WordPress2
5. Fluent Forms Fluent Forms plugin1

Recent Vulnerabilities

See more →
CVE-2024-10646
CVSS 7.2high

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject

Dec 14, 2024
CVE-2024-9651
CVSS 6.1EPSS 0%medium

Contact Form Plugin by Fluent Forms < 5.2.1 - Admin+ Stored XSS

Dec 9, 2024🔧 No Patch
CVE-2024-9528
CVSS 4.9EPSS 0%medium

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting

Oct 5, 2024
CVE-2024-5053
CVSS 4.3medium

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification

Sep 1, 2024🔧 No Patch
CVE-2024-6703
CVSS 5.4EPSS 0%medium

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Welcome Screen Fields

Jul 27, 2024
CVE-2024-6518
CVSS 4.8EPSS 0%medium

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jul 27, 2024
CVE-2024-6520
CVSS 4.8EPSS 0%medium

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jul 27, 2024
CVE-2024-6521
CVSS 4.8EPSS 0%medium

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jul 27, 2024
CVE-2024-4157
CVSS 8.8EPSS 0%high

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValues

May 22, 2024🔧 No Patch
CVE-2024-4709
CVSS 6.4EPSS 0%medium

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 18, 2024🔧 No Patch

Monitor fluentforms in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.