CVE · Medium

CVE-2025-13722 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13722 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.8 Missing Authorization Medium 5.3 < 6.1.8 6.1.8 2026-01-06

CVE-2025-13722

The Fluent Forms plugin, up to version 6.1.7, is susceptible to a missing authorization vulnerability in its `fluentform_ai_create_form` AJAX action. Authenticated users, including those with at least Subscriber-level access, can exploit this flaw to create any form using the publicly accessible AI builder, despite lacking proper capability checks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.