Plugin Vulnerability Hub
Plugin 28 known issues Latest disclosed Apr 16, 2026

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Vulnerabilities

Review known vulnerability records for the WordPress plugin Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder (`fluentform`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-4160, CVE-2026-0996 and CVE-2025-69001, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
28
High or Critical
7
Patch Coverage
100%
Last Updated
Apr 16, 2026
Priority CVE Quick Links

Fast paths into Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
28
CVE-2024-2771 Critical 5.1.17
CVE-2024-2771 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Privilege Escalation

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation

CVE-2021-34620 High 3.6.67
CVE-2021-34620 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Stored Cross-Site Scripting

WP Fluent Forms < 3.6.67 - Stored Cross-Site Scripting

CVE-2022-3463 High 4.3.13
CVE-2022-3463 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Vulnerability

Contact Form Plugin by FluentForm <= 4.3.12 - CSV Injection

CVE-2024-4157 High 5.1.16
CVE-2024-4157 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Vulnerability

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValues

CVE-2024-2782 High 5.1.17
CVE-2024-2782 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Vulnerability

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation

CVE-2024-10646 High 5.2.7
CVE-2024-10646 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Stored Cross-Site Scripting

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject

CVE-2023-24410 High 5.0.0
CVE-2023-24410 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder SQL Injection

FluentForm <= 4.3.25 - Authenticated (Administrator+) SQL Injection

CVE-2025-69001 Medium 6.1.12
CVE-2025-69001 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Vulnerability

FluentForm <= 6.1.11 - Unauthenticated Arbitrary Shortcode Execution

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
28 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 6 high severity findings.
Recent CVEs
CVE-2026-4160, CVE-2026-0996 and CVE-2025-69001
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

CVE-2026-4160 Medium Patch path listed

CVE-2026-4160: Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' para...

Published
Apr 16, 2026
Patch Status
6.2.0
Known Vulnerabilities

Reports for Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-4160
CVE-2026-4160: Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and o...

Published
Apr 16, 2026
Patched Release
6.2.0
Affected Versions
6.1.21 through 6.1.21
Next Step
Update to 6.2.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-0996
CVE-2026-0996: Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module

The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all versions up to, and including, 6.1.14 due to a combination of missing authorization checks, a leaked nonce, and insufficient input sanitization. The vulnerabil...

Published
Feb 09, 2026
Patched Release
6.1.15
Affected Versions
Versions up to 6.1.14
Next Step
Update to 6.1.15 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-69001
CVE-2025-69001: FluentForm <= 6.1.11 - Unauthenticated Arbitrary Shortcode Execution

The The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.1.11. This is due to the software allowing users to execute an action that do...

Published
Jan 13, 2026
Patched Release
6.1.12
Affected Versions
Versions up to 6.1.11
Next Step
Update to 6.1.12 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13722
CVE-2025-13722: Fluent Forms <= 6.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX act...

Published
Jan 06, 2026
Patched Release
6.1.8
Affected Versions
Versions up to 6.1.7
Next Step
Update to 6.1.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13748
CVE-2025-13748: Fluent Forms <= 6.1.7 - Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.1.7 via the 'submission_id' parameter due to missing validation on a user cont...

Published
Dec 05, 2025
Patched Release
6.1.8
Affected Versions
Versions up to 6.1.7
Next Step
Update to 6.1.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-9260
CVE-2025-9260: Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes it possible for...

Published
Sep 02, 2025
Patched Release
6.1.2
Affected Versions
5.1.16 through 6.1.1
Next Step
Update to 6.1.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-3615
CVE-2025-3615: Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Co...

Published
Apr 16, 2025
Patched Release
6.0.3
Affected Versions
Versions up to 6.0.2
Next Step
Update to 6.0.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13666
CVE-2024-13666: Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a p...

Published
Mar 21, 2025
Patched Release
6.0.0
Affected Versions
Versions up to 5.2.12
Next Step
Update to 6.0.0 or newer if supported.
Plugin High Patched: Yes CVE-2024-10646
CVE-2024-10646: Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and outp...

Published
Dec 13, 2024
Patched Release
5.2.7
Affected Versions
Versions up to 5.2.6
Next Step
Update to 5.2.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-9651
CVE-2024-9651: Fluent Forms <= 5.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping....

Published
Nov 18, 2024
Patched Release
5.2.1
Affected Versions
Versions up to 5.2.0
Next Step
Update to 5.2.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-9528
CVE-2024-9528: Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form label fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escapin...

Published
Oct 04, 2024
Patched Release
5.1.20
Affected Versions
Versions up to 5.1.19
Next Step
Update to 5.1.20 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-5053
CVE-2024-5053: Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in all versions up to, and including, 5.1.18...

Published
Aug 31, 2024
Patched Release
5.1.19
Affected Versions
Versions up to 5.1.18
Next Step
Update to 5.1.19 or newer if supported.