Impact
The vulnerability resides in the Fluent Forms WordPress plugin, whereby an attacker can embed crafted JavaScript code through the {get.NAME} SmartCode placeholder used within Custom HTML fields. When a form containing such a placeholder is rendered and a user follows a malicious link, the arbitrary script executes in the victim’s browser, allowing data theft, session hijacking, or other client‑side attacks. The weakness is a classic input validation and output escaping flaw, classified as CWE‑79.
Affected Systems
This flaw affects all installations of the wpmanageninja Fluent Forms plugin up to and including version 6.2.14. The issue is triggered only when the site administrator has configured a Custom HTML field that contains a {get.*} SmartCode and places it inside a URL‑accepting attribute such as an iframe src or an a href attribute.
Risk and Exploitability
The CVSS score of 4.7 suggests a low‑to‑moderate severity. The EPSS score is not available, indicating insufficient data on real‑world exploitation activity. The vulnerability is not listed in CISA’s KEV catalog, which reduces the confidence in imminent widespread attacks. Exploitation requires the plugin to be installed, the vulnerable field to be active, and a victim to click a crafted link, so the attack surface is somewhat constrained. Nonetheless, the possibility of automatic script execution in users’ browsers warrants prompt remediation.
OpenCVE Enrichment