Known vulnerabilities in the Fluent Forms plugin
10 security advisories have been published for the Fluent Forms plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Fluent Forms - Cross-Site Scripting (XSS) (CVE-2026-11881) MEDIUM
- Fluent Forms - Broken Access Control (CVE-2026-5069) MEDIUM
- Fluent Forms - Security Vulnerability (CVE-2026-11578) LOW
- Fluent Forms - Security Vulnerability (CVE-2026-11880) LOW
- Fluent Forms - Broken Access Control (CVE-2026-5396) HIGH
- Fluent Forms - Security Vulnerability (CVE-2026-6344) MEDIUM
- Fluent Forms - Broken Access Control (CVE-2026-0996) MEDIUM
- Fluent Forms - Cross-Site Scripting (XSS) (CVE-2025-3615) MEDIUM
- Fluent Forms - Cross-Site Scripting (XSS) (CVE-2024-9651) MEDIUM
- Fluent Forms - Cross-Site Scripting (XSS) (CVE-2023-6957) MEDIUM