CVE · Medium

CVE-2026-6344 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-6344 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.2 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.9 < 6.2.2 6.2.2 2026-05-05

CVE-2026-6344

The Fluent Forms plugin for WordPress versions up to 6.2.1 is susceptible to an Arbitrary File Read vulnerability due to inadequate path validation in the getAttachments() method of EmailNotificationActions. Attackers with administrator access can exploit this by submitting a specially crafted file-upload URL that bypasses path checks, allowing them to read sensitive files like wp-config.php through email notifications.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.