CVE-2026-18146
- EPSS 0.36%
- Veröffentlicht 13.08.2026 06:38:30
- Zuletzt bearbeitet 14.08.2026 19:09:56
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insuffi...
CVE-2026-17571
- EPSS 0.21%
- Veröffentlicht 01.08.2026 09:17:01
- Zuletzt bearbeitet 12.08.2026 21:00:37
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in all versions up to, and including, 6.2.8 due to insufficient input sanitiza...
CVE-2026-17567
- EPSS 0.38%
- Veröffentlicht 31.07.2026 09:32:01
- Zuletzt bearbeitet 12.08.2026 21:00:37
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter due to missi...
CVE-2026-16655
- EPSS 0.3%
- Veröffentlicht 29.07.2026 09:31:14
- Zuletzt bearbeitet 30.07.2026 14:01:30
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to in...
CVE-2026-5069
- EPSS 0.17%
- Veröffentlicht 10.07.2026 02:30:39
- Zuletzt bearbeitet 10.07.2026 19:17:27
The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX fl...