CVE · Medium

CVE-2026-6828 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-6828 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 6.2.2 6.2.2 2026-05-12

CVE-2026-6828

The Fluent Forms plugin, used for creating various forms on WordPress sites up to version 6.2.1, is susceptible to stored cross-site scripting (XSS) attacks through the 'permission_message' parameter. Authenticated users with contributor-level access or higher can inject malicious scripts that will run in any user's browser when they view the affected pages.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.