CVE-2026-66633: WordPress Fluent Forms Pro Add On Pack plugin < 6.2.12 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
Affected Software
1 affected component
wordpress/fluent-forms-pro-add-on-pack<6.2.12
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Fluent Forms Pro Add On Pack pluginto a version that resolves this vulnerability.Fixed in 6.2.12
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed, and does exploitation require authentication?
Sites running Fluent Forms Pro Add On Pack versions earlier than 6.2.12 are affected. The vulnerability is described as unauthenticated, so an attacker does not need an account or existing privileges.
2
What conditions are needed for an attacker to exploit this issue?
The attack vector is network-based and has low attack complexity, but user interaction is required. Successful exploitation can affect confidentiality, integrity, and availability at low impact, with scope changed.