Description
The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it.
Published:
2026-07-30
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 30 Jul 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fluent Forms
Fluent Forms fluent Forms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Fluent Forms
Fluent Forms fluent Forms Wordpress Wordpress wordpress |
Thu, 30 Jul 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it. | |
| Title | Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-30T06:00:10.415Z
Reserved: 2026-06-10T13:25:36.909Z
Link: CVE-2026-11881
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T08:15:04Z
Weaknesses
No weakness.