CVE-2025-3615: Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3615?
CVE-2025-3615 is classified as a medium severity vulnerability due to its potential for exploitation through stored cross-site scripting.
How do I fix CVE-2025-3615?
To mitigate CVE-2025-3615, update the Fluent Forms plugin to version 6.0.3 or later.
Who is affected by CVE-2025-3615?
Authenticated users of the Fluent Forms plugin for WordPress versions up to and including 6.0.2 are affected by CVE-2025-3615.
What kind of vulnerability is CVE-2025-3615?
CVE-2025-3615 is a stored cross-site scripting vulnerability caused by insufficient input sanitization and output escaping.
Can CVE-2025-3615 be exploited remotely?
Yes, CVE-2025-3615 can be exploited by authenticated attackers who can submit forms through the vulnerable plugin.