WordPress 3 vulnerabilities

Is the Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin safe?

Below are the known, publicly disclosed vulnerabilities of the Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder (WordPress) component. If you use it on your site, check the version and update it before the flaw gets exploited.

Using the Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin? Check for free whether your site is vulnerable through it, or have us update and secure it.

Known vulnerabilities

Wysoka · CVSS 7.2 CVE-2026-18146 August 13, 2026

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder: cross-site scripting (XSS)

Cross-site scripting (XSS) w komponencie Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder. Ocena zagrożenia: Wysoka (CVSS 7.2). Zaktualizuj podatny komponent do najnowszej wersji lub tymczasowo go wyłącz.

Wysoka · CVSS 7.2 CVE-2026-16655 July 29, 2026

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder: cross-site scripting (XSS)

Cross-site scripting (XSS) w komponencie Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder. Ocena zagrożenia: Wysoka (CVSS 7.2). Zaktualizuj podatny komponent do najnowszej wersji lub tymczasowo go wyłącz.

Wysoka · CVSS 8.2 CVE-2026-5395 May 14, 2026

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder: podatność bezpieczeństwa

Podatność bezpieczeństwa w komponencie Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder. Ocena zagrożenia: Wysoka (CVSS 8.2). Zaktualizuj podatny komponent do najnowszej wersji lub tymczasowo go wyłącz.

How to check whether this affects you

  • Check the installed version of the Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder component in the admin panel.
  • Compare it with the fixed version noted in the details of the relevant vulnerability above.
  • If your version is older, update the component to the latest available.
  • If a fix has not been released yet, temporarily disable the vulnerable element and watch your logs.
Do not guess, check

Is this plugin putting your site at risk?

We will run a free audit: we check versions, plugins and configuration, and tell you plainly whether you are safe.

Request a free audit →