Impact
The Fluent Forms WordPress plugin before version 6.2.6 fails to sanitize a form field configuration setting that is output inside an inline script, a flaw identified as CWE‑79, a classic client‑side stored XSS vulnerability. A contributor who manages forms can inject arbitrary JavaScript into this setting. When the form is rendered the injected code executes in the browsers of any visitor who loads the form, including administrators previewing it.
Affected Systems
WordPress sites that use the Fluent Forms plugin with any version earlier than 6.2.6. The flaw is exploitable by users who hold a Contributor role or higher with form‑management permissions but lack the unfiltered_html capability, such as in a multisite environment.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, and the EPSS score of less than 1 % suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to create or alter a form’s date/time field configuration through the WordPress admin interface. Once the malicious script is stored, any visitor who loads that form—regardless of their role—will have the script executed in their browser.
OpenCVE Enrichment