The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 30 Jul 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fluent Forms
Fluent Forms fluent Forms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Fluent Forms
Fluent Forms fluent Forms Wordpress Wordpress wordpress |
Thu, 30 Jul 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it. | |
| Title | Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-30T06:00:10.415Z
Reserved: 2026-06-10T13:25:36.909Z
Link: CVE-2026-11881
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T08:15:04Z
Weaknesses
No weakness.