Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Information

Software Type Plugin
Software Slug fluentform (view on wordpress.org)
Software Status Active
Software Author wpmanageninja
Software Website wpmanageninja.com
Software Downloads 17,765,172
Software Active Installs 700,000
Software Record Last Updated July 22, 2026

Showing 1-20 of 34 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Fluent Forms <= 6.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id' Patched CVE-2026-5069 5.4 Fernando Mecozzi July 9, 2026
Fluent Forms <= 6.2.0 - Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter Patched CVE-2026-5395 8.2 Sander Horsman May 13, 2026
Fluent Forms <= 6.1.21 - Authenticated (Subscriber+) Authorization Bypass via 'form_id' Parameter Patched CVE-2026-5396 8.2 Sander Horsman May 13, 2026
Fluent Forms <= 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'permission_message' Shortcode Attribute Patched CVE-2026-6828 6.4 zaim May 12, 2026
Fluent Forms <= 6.2.1 - Authenticated (Administrator+) Arbitrary File Read via Path Traversal in Email Attachment Patched CVE-2026-6344 4.9 Niv Kochan May 5, 2026
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification Patched CVE-2026-4160 5.3 Prickly Cactus April 16, 2026
Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module Patched CVE-2026-0996 6.4 Osvaldo Noe Gonzalez Del Rio (Os) February 9, 2026
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.14 - Missing Authorization Patched CVE-2026-25313 4.3 benzdeus January 25, 2026
FluentForm <= 6.1.11 - Unauthenticated Arbitrary Shortcode Execution Patched CVE-2025-69001 6.5 Kishan Vyas January 13, 2026
Fluent Forms <= 6.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder Patched CVE-2025-13722 5.3 Marcin Dudek (dudekmar) January 6, 2026
Fluent Forms <= 6.1.7 - Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id Patched CVE-2025-13748 5.3 Md. Moniruzzaman Prodhan (NomanProdhan) December 5, 2025
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read Patched CVE-2025-9260 6.5 Webbernaut September 2, 2025
Fluent Forms <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2025-3615 6.4 Asaf Mozes April 16, 2025
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing Patched CVE-2024-13666 5.3 shaman0x01 March 21, 2025
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 - Unauthenticated Stored Cross-Site Scripting via Form Subject Patched CVE-2024-10646 7.2 mikemyers December 13, 2024
Fluent Forms <= 5.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2024-9651 4.4 Krugov Artyom November 18, 2024
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting Patched CVE-2024-9528 4.9 Ivan Kuzymchak October 4, 2024
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification Patched CVE-2024-5053 4.2 Tobias Weißhaar (kun_19) August 31, 2024
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting Patched CVE-2024-6520 4.4 Joel Indra July 26, 2024
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Administrator+) Stored Cross-Site Scripting Patched CVE-2024-6518 4.4 Joel Indra July 26, 2024

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation