Description
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated Cross Site Scripting flaw in the Fluent Forms Pro Add On Pack plugin. It allows an attacker to inject arbitrary JavaScript into web pages that users view, potentially enabling session hijacking, cookie theft, defacement or other client‑side malicious actions. The flaw can be leveraged without authentication, meaning any user visiting a vulnerable page could be affected.

Affected Systems

WPManageNinja’s Fluent Forms Pro Add On Pack plugin, versions older than 6.2.12. No other product variations or versions are listed.

Risk and Exploitability

A CVSS score of 7.1 classifies the issue as High severity. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified from the data, but the vulnerability is publicly known and could be widely used. The flaw is not listed in CISA’s KEV catalog. Because access is unauthenticated, attackers can exploit the weakness simply by sending a crafted request to a vulnerable form or configuration endpoint, with the malicious script being stored or delivered to other site users.

Generated by OpenCVE AI on August 18, 2026 at 15:49 UTC.

Remediation

Vendor Solution

Update the WordPress Fluent Forms Pro Add On Pack Plugin to the latest available version (at least 6.2.12).


OpenCVE Recommended Actions

  • Update the WordPress Fluent Forms Pro Add On Pack Plugin to version 6.2.12 or later.
  • If an immediate update is not possible, disable the plugin for unauthenticated users or restrict administrative access to trusted roles.
  • Examine any custom form content or HTML added through the plugin and ensure that inputs are properly sanitized and escaped to prevent script injection.

Generated by OpenCVE AI on August 18, 2026 at 15:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpmanageninja
Wpmanageninja fluent Forms Pro Add On Pack
Vendors & Products Wordpress
Wordpress wordpress
Wpmanageninja
Wpmanageninja fluent Forms Pro Add On Pack

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
Title WordPress Fluent Forms Pro Add On Pack plugin < 6.2.12 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wpmanageninja Fluent Forms Pro Add On Pack
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T21:25:51.292Z

Reserved: 2026-07-27T14:00:34.306Z

Link: CVE-2026-66633

cve-icon Vulnrichment

Updated: 2026-08-18T19:40:12.313Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:16:57.823

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-66633

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:33:42Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')