PLUGIN SECURITY

Is Fluentform safe?

Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.

What this plugin does

  • Slug: fluentform
  • Author: WPManageNinja
  • 700000+ active installs
  • 96/100 rating (789 reviews on wordpress.org)
  • 19041300 all-time downloads
  • On WordPress.org since 2017-12-29

contact formcustom formform builderformsWP Forms

Maintenance status

  • Latest known version: 6.2.11
  • Last updated: 2026-08-22 11:34am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

41 known CVEs on file for Fluentform.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-17571 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 6.2.9 6.2.9 2026-07-31 ✓ fixed in latest
CVE-2026-18146 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 6.2.12 6.2.12 2026-07-31 ⚠ update needed
CVE-2026-11881 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 6.2.6 6.2.6 2026-07-30 ✓ fixed in latest
CVE-2026-17567 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.9 Authorization Bypass Through User-Controlled Key Medium 5.3 < 6.2.9 6.2.9 2026-07-30 ✓ fixed in latest
CVE-2026-16655 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 6.2.8 6.2.8 2026-07-28 ✓ fixed in latest
CVE-2026-5069 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.2 Incorrect Authorization Medium 5.4 < 6.2.2 6.2.2 2026-07-09 ✓ fixed in latest
CVE-2026-11578 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.5 Authorization Bypass Through User-Controlled Key Unknown < 6.2.5 6.2.5 2026-07-02 ✓ fixed in latest
CVE-2026-11880 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.1 Authorization Bypass Through User-Controlled Key Unknown < 6.2.1 6.2.1 2026-07-01 ✓ fixed in latest
+ 39 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-5396 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.0 Authorization Bypass Through User-Controlled Key High 8.2 < 6.2.0 6.2.0 2026-05-13 ✓ fixed in latest
CVE-2026-5395 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.1 Authorization Bypass Through User-Controlled Key High 8.2 < 6.2.1 6.2.1 2026-05-13 ✓ fixed in latest
CVE-2026-6828 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 6.2.2 6.2.2 2026-05-12 ✓ fixed in latest
CVE-2026-6344 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.2 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.9 < 6.2.2 6.2.2 2026-05-05 ✓ fixed in latest
CVE-2026-4160 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.0 Authorization Bypass Through User-Controlled Key Medium 5.3 < 6.2.0 6.2.0 2026-04-16 ✓ fixed in latest
CVE-2026-25313 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.15 Missing Authorization Medium 4.3 < 6.1.15 6.1.15 2026-01-25 ✓ fixed in latest
CVE-2025-69001 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.12 Improper Control of Generation of Code ('Code Injection') Medium 5.3 < 6.1.12 6.1.12 2026-01-13 ✓ fixed in latest
CVE-2025-13722 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.8 Missing Authorization Medium 5.3 < 6.1.8 6.1.8 2026-01-06 ✓ fixed in latest
CVE-2025-13748 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.8 Authorization Bypass Through User-Controlled Key Medium 5.3 < 6.1.8 6.1.8 2025-12-05 ✓ fixed in latest
CVE-2024-13666 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.0.0 Improper Input Validation Medium 5.3 < 6.0.0 6.0.0 2025-03-21 ✓ fixed in latest
CVE-2024-10646 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.2.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 5.2.7 5.2.7 2024-12-13 ✓ fixed in latest
CVE-2024-9651 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.2.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.2.1 5.2.1 2024-11-18 ✓ fixed in latest
CVE-2024-9528 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 5.1.20 5.1.20 2024-10-04 ✓ fixed in latest
CVE-2024-5053 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.19 Improper Authorization Medium 4.3 < 5.1.19 5.1.19 2024-08-31 ✓ fixed in latest
CVE-2024-6520 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 5.1.20 5.1.20 2024-07-26 ✓ fixed in latest
CVE-2024-6703 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.1.20 5.1.20 2024-07-26 ✓ fixed in latest
CVE-2024-6518 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 5.1.20 5.1.20 2024-07-26 ✓ fixed in latest
CVE-2024-6521 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 5.1.20 5.1.20 2024-07-26 ✓ fixed in latest
CVE-2024-4157 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.16 Deserialization of Untrusted Data High 8.8 < 5.1.16 5.1.16 2024-05-21 ✓ fixed in latest
CVE-2024-2782 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.17 Missing Authorization High 7.5 < 5.1.17 5.1.17 2024-05-17 ✓ fixed in latest
CVE-2024-2771 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.17 Missing Authorization Critical 9.8 < 5.1.17 5.1.17 2024-05-17 ✓ fixed in latest
CVE-2024-2772 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.1.14 5.1.14 2024-05-17 ✓ fixed in latest
CVE-2024-4709 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.1.17 5.1.17 2024-05-17 ✓ fixed in latest
CVE-2023-6957 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.1.10 5.1.10 2024-03-05 ✓ fixed in latest
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.7 Unknown < 5.1.7 5.1.7 2024-01-19 ✓ fixed in latest
CVE-2024-0618 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.1.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 5.1.7 5.1.7 2024-01-18 ✓ fixed in latest
CVE-2023-41952 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.0.9 Missing Authorization Medium 5.3 < 5.0.9 5.0.9 2023-09-08 ✓ fixed in latest
CVE-2023-24410 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.0.0 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 5.5 < 5.0.0 5.0.0 2023-07-12 ✓ fixed in latest
CVE-2023-0546 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 4.3.25 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.3.25 4.3.25 2023-03-20 ✓ fixed in latest
CVE-2022-3463 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 4.3.13 Improper Neutralization of Formula Elements in a CSV File Critical 9.8 < 4.3.13 4.3.13 2022-10-17 ✓ fixed in latest
CVE-2021-34620 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 3.6.67 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 8.8 < 3.6.67 3.6.67 2021-06-16 ✓ fixed in latest
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.0.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 6.0.3 6.0.3 0000-00-00 ✓ fixed in latest
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.15 Unknown < 6.1.15 6.1.15 0000-00-00 ✓ fixed in latest
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.2 Medium 6.5 < 6.1.2 6.1.2 0000-00-00 ✓ fixed in latest
CVE-2023-41952 Contact Form for Plugin by Fluent Forms < 5.0.9 - Insecure Direct Object Reference Unknown < 5.0.9 5.0.9 ✓ fixed in latest
CVE-2024-0618 Fluent Forms < 5.1.7 - Admin+ Stored Cross-Site Scripting via imported form title Unknown < 5.1.7 5.1.7 ✓ fixed in latest
CVE-2025-3615 Fluent Forms < 6.0.3 - Contributor+ Stored XSS Unknown < 6.0.3 6.0.3 ✓ fixed in latest
CVE-2025-9260 Fluent Forms 5.1.16 - 6.1.0 - Subscriber+ PHP Object Injection To Arbitrary File Read Unknown < 6.1.1 6.1.1 ✓ fixed in latest
CVE-2026-0996 Fluent Forms < 6.1.15 - Subscriber+ Stored XSS Unknown < 6.1.15 6.1.15 ✓ fixed in latest

How to fix it

Keep Fluentform updated — 6.2.11 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.