The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it.
History

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Fluent Forms
Fluent Forms fluent Forms
Wordpress
Wordpress wordpress
Vendors & Products Fluent Forms
Fluent Forms fluent Forms
Wordpress
Wordpress wordpress

Thu, 30 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it.
Title Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-07-30T06:00:10.415Z

Updated: 2026-07-30T12:36:35.949Z

Reserved: 2026-06-10T13:25:36.909Z

Link: CVE-2026-11881

cve-icon Vulnrichment

Updated: 2026-07-30T12:36:32.177Z

cve-icon NVD

No data.

cve-icon Redhat

No data.