PLUGIN SECURITY
Is Fluent Crm safe?
The easiest and fastest Email Marketing, Newsletter, Marketing Automation Plugin & CRM Solution for WordPress
What this plugin does
- Slug:
fluent-crm - Author: WPManageNinja
- 80000+ active installs
- 96/100 rating (249 reviews on wordpress.org)
- 1807505 all-time downloads
- On WordPress.org since 2020-09-29
crmEmail Marketingemail newsletternewslettersubscribers
Maintenance status
- Latest known version: 3.1.10
- Last updated: 2026-08-24 12:14pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
5 known CVEs on file for Fluent Crm. Reported between 2023 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-7798 | FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 3.0.0 | Server-Side Request Forgery (SSRF) | Medium 5.4 | < 3.0.0 | 3.0.0 | 2026-05-21 | ✓ fixed in latest |
| CVE-2026-57715 | FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 3.1.8 | — | High 7.1 | < 3.1.8 | 3.1.8 | 2026-05-21 | ✓ fixed in latest |
| CVE-2025-12935 | FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 2.9.85 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.9.85 | 2.9.85 | 2025-11-20 | ✓ fixed in latest |
| CVE-2024-30430 | FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 2.8.45 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 2.8.45 | 2.8.45 | 2024-03-28 | ✓ fixed in latest |
| CVE-2023-1430 | FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 2.8.02 | Use of a One-Way Hash without a Salt | Low 3.7 | < 2.8.02 | 2.8.02 | 2023-06-01 | ✓ fixed in latest |
How to fix it
Keep Fluent Crm updated — 3.1.10 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Hostinger Reach – AI-Powered Email Marketing for WordPress — 1000000+ active installs — 100/100 (6) — max PHP 8.4
- Flamingo — 800000+ active installs — 84/100 (121) — max PHP 8.4
- MailPoet – Newsletters, Email Marketing, and Automation — 500000+ active installs — 88/100 (1431)
- HubSpot All-In-One Marketing – Forms, Popups, Live Chat — 200000+ active installs — 86/100 (207) — max PHP 8.4
- Newsletter – Send awesome emails from WordPress — 200000+ active installs — 92/100 (1203) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.