Description
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'any attacker-chosen name matching the {get.NAME} placeholder (PoC uses 'proof')' parameter in all versions up to, and including, 6.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires a site administrator to have configured a Custom HTML field on a published form containing a {get.*} SmartCode inside a URL-accepting attribute such as iframe src or a href — a documented Fluent Forms feature.
Published: 2026-10-10
Score: 4.7 Medium
EPSS: n/a
KEV: No
Impact: Reflected Cross-Site Scripting
Action: Patch
AI Analysis

Impact

The vulnerability resides in the Fluent Forms WordPress plugin, whereby an attacker can embed crafted JavaScript code through the {get.NAME} SmartCode placeholder used within Custom HTML fields. When a form containing such a placeholder is rendered and a user follows a malicious link, the arbitrary script executes in the victim’s browser, allowing data theft, session hijacking, or other client‑side attacks. The weakness is a classic input validation and output escaping flaw, classified as CWE‑79.

Affected Systems

This flaw affects all installations of the wpmanageninja Fluent Forms plugin up to and including version 6.2.14. The issue is triggered only when the site administrator has configured a Custom HTML field that contains a {get.*} SmartCode and places it inside a URL‑accepting attribute such as an iframe src or an a href attribute.

Risk and Exploitability

The CVSS score of 4.7 suggests a low‑to‑moderate severity. The EPSS score is not available, indicating insufficient data on real‑world exploitation activity. The vulnerability is not listed in CISA’s KEV catalog, which reduces the confidence in imminent widespread attacks. Exploitation requires the plugin to be installed, the vulnerable field to be active, and a victim to click a crafted link, so the attack surface is somewhat constrained. Nonetheless, the possibility of automatic script execution in users’ browsers warrants prompt remediation.

Generated by OpenCVE AI on October 10, 2026 at 05:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Fluent Forms plugin to the latest version that removes the vulnerability
  • If updating immediately is not possible, disable any Custom HTML fields or remove all {get.*} placeholders from existing forms
  • Apply WordPress output sanitization functions to any custom HTML that may contain query parameters to ensure proper escaping of user‑supplied data

Generated by OpenCVE AI on October 10, 2026 at 05:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'any attacker-chosen name matching the {get.NAME} placeholder (PoC uses 'proof')' parameter in all versions up to, and including, 6.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires a site administrator to have configured a Custom HTML field on a published form containing a {get.*} SmartCode inside a URL-accepting attribute such as iframe src or a href — a documented Fluent Forms feature.
Title Fluent Forms <= 6.2.14 - Reflected Cross-Site Scripting via '{get.*}' Editor SmartCode Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T04:26:43.617Z

Reserved: 2026-09-28T13:55:51.706Z

Link: CVE-2026-101324

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T05:16:38.733

Modified: 2026-10-10T05:16:38.733

Link: CVE-2026-101324

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T05:30:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')