Plugin Vulnerability Hub
Plugin 33 known issues Latest disclosed May 13, 2026

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Vulnerabilities

Review known vulnerability records for the WordPress plugin Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder (`fluentform`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-5395, CVE-2026-5396 and CVE-2026-6828, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
33
High or Critical
9
Patch Coverage
100%
Last Updated
May 14, 2026
Related Security Guides

Use these guides while reviewing Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
33
1. Match the Package
Confirm the installed WordPress plugin slug is fluentform before acting on any CVE from this cluster.
2. Sort by Severity
Start with 9 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
33 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
33
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2024-2771
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builde...
Privilege Escalation Versions up to 5.1.16 5.1.17 CVSS 9.8
CVE-2021-34620
WP Fluent Forms < 3.6.67 - Stored Cross-Site Scripting
Stored Cross-Site Scripting Versions before 3.6.67 3.6.67 CVSS 8.8
CVE-2022-3463
Contact Form Plugin by FluentForm <= 4.3.12 - CSV Injection
Vulnerability Versions up to 4.3.12 4.3.13 CVSS 8.3
CVE-2026-5395
Fluent Forms <= 6.2.0 - Authenticated (Subscriber+) Authorization Bypass via 'table'...
Authorization Bypass Versions up to 6.2.0 6.2.1 CVSS 8.2
CVE-2026-5396
Fluent Forms <= 6.1.21 - Authenticated (Subscriber+) Authorization Bypass via 'form_...
Authorization Bypass Versions up to 6.1.21 6.2.0 CVSS 8.2
CVE-2024-4157
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builde...
Vulnerability Versions up to 5.1.15 5.1.16 CVSS 7.5
CVE-2024-2782
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builde...
Vulnerability Versions up to 5.1.16 5.1.17 CVSS 7.5
CVE-2024-10646
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builde...
Stored Cross-Site Scripting Versions up to 5.2.6 5.2.7 CVSS 7.2
CVE-2024-2771 Critical 5.1.17
CVE-2024-2771 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Privilege Escalation

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation

CVE-2021-34620 High 3.6.67
CVE-2021-34620 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Stored Cross-Site Scripting

WP Fluent Forms < 3.6.67 - Stored Cross-Site Scripting

CVE-2022-3463 High 4.3.13
CVE-2022-3463 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Vulnerability

Contact Form Plugin by FluentForm <= 4.3.12 - CSV Injection

CVE-2026-5395 High 6.2.1
CVE-2026-5395 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Authorization Bypass

Fluent Forms <= 6.2.0 - Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter

CVE-2026-5396 High 6.2.0
CVE-2026-5396 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Authorization Bypass

Fluent Forms <= 6.1.21 - Authenticated (Subscriber+) Authorization Bypass via 'form_id' Parameter

CVE-2024-4157 High 5.1.16
CVE-2024-4157 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Vulnerability

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValues

CVE-2024-2782 High 5.1.17
CVE-2024-2782 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Vulnerability

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation

CVE-2024-10646 High 5.2.7
CVE-2024-10646 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Stored Cross-Site Scripting

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
33 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 8 high severity findings.
Recent CVEs
CVE-2026-5395, CVE-2026-5396 and CVE-2026-6828
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-5395
CVE-2026-5395: Fluent Forms <= 6.2.0 - Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to missing validation on a user control...

Published
May 13, 2026
Patched Release
6.2.1
Affected Versions
Versions up to 6.2.0
Next Step
Update to 6.2.1 or newer if supported.
Plugin High Patched: Yes CVE-2026-5396
CVE-2026-5396: Fluent Forms <= 6.1.21 - Authenticated (Subscriber+) Authorization Bypass via 'form_id' Parameter

The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authorizing submission-level actions (read, modify, delete, add notes) based on a user-s...

Published
May 13, 2026
Patched Release
6.2.0
Affected Versions
Versions up to 6.1.21
Next Step
Update to 6.2.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-6828
CVE-2026-6828: Fluent Forms <= 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'permission_message' Shortcode Attribute

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permission_message' parameter in all versions up to, and including, 6.2.1 due to insufficient input sanitization a...

Published
May 12, 2026
Patched Release
6.2.2
Affected Versions
Versions up to 6.2.1
Next Step
Update to 6.2.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-6344
CVE-2026-6344: Fluent Forms <= 6.2.1 - Authenticated (Administrator+) Arbitrary File Read via Path Traversal in Email Attachment

The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attacker-supplied file-upload URLs into filesys...

Published
May 05, 2026
Patched Release
6.2.2
Affected Versions
Versions up to 6.2.1
Next Step
Update to 6.2.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-4160
CVE-2026-4160: Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to missing authorization and o...

Published
Apr 16, 2026
Patched Release
6.2.0
Affected Versions
6.1.21 through 6.1.21
Next Step
Update to 6.2.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-0996
CVE-2026-0996: Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module

The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all versions up to, and including, 6.1.14 due to a combination of missing authorization checks, a leaked nonce, and insufficient input sanitization. The vulnerabil...

Published
Feb 09, 2026
Patched Release
6.1.15
Affected Versions
Versions up to 6.1.14
Next Step
Update to 6.1.15 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-25313
CVE-2026-25313: Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.14 - Missing Authorization

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.1.14. This makes it possible for authentica...

Published
Jan 25, 2026
Patched Release
6.1.15
Affected Versions
Versions up to 6.1.14
Next Step
Update to 6.1.15 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-69001
CVE-2025-69001: FluentForm <= 6.1.11 - Unauthenticated Arbitrary Shortcode Execution

The The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.1.11. This is due to the software allowing users to execute an action that do...

Published
Jan 13, 2026
Patched Release
6.1.12
Affected Versions
Versions up to 6.1.11
Next Step
Update to 6.1.12 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13722
CVE-2025-13722: Fluent Forms <= 6.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX act...

Published
Jan 06, 2026
Patched Release
6.1.8
Affected Versions
Versions up to 6.1.7
Next Step
Update to 6.1.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13748
CVE-2025-13748: Fluent Forms <= 6.1.7 - Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.1.7 via the 'submission_id' parameter due to missing validation on a user cont...

Published
Dec 05, 2025
Patched Release
6.1.8
Affected Versions
Versions up to 6.1.7
Next Step
Update to 6.1.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-9260
CVE-2025-9260: Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes it possible for...

Published
Sep 02, 2025
Patched Release
6.1.2
Affected Versions
5.1.16 through 6.1.1
Next Step
Update to 6.1.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-3615
CVE-2025-3615: Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Co...

Published
Apr 16, 2025
Patched Release
6.0.3
Affected Versions
Versions up to 6.0.2
Next Step
Update to 6.0.3 or newer if supported.