Impact
The vulnerability in the Fluent Forms WordPress plugin allows a stored XSS flaw to be inserted into notification smartcode values. The lack of input sanitization and output escaping means an attacker can embed malicious scripts in elements such as the email subject or static Send To field. When an administrator loads the form’s submission logs, the script executes in that administrator’s browser, potentially granting the attacker the ability to steal session cookies, deface the site, or perform other malicious actions in the admin context.
Affected Systems
WordPress sites running the Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin, in any version up to and including 6.2.11, are affected.
Risk and Exploitability
The flaw carries a CVSS score of 7.2 and is not listed in the CISA KEV catalog. EPSS data is unavailable, but the attack requires only unauthenticated abuse of the form submission process to embed the payload, and later requires an administrator to view the logs to trigger execution. This combination of easy injection and limited scope of impact keeps the overall risk at a medium‑to‑high level for sites that expose the form to untrusted users and rely on the vulnerable notification templates.
OpenCVE Enrichment