Description
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permission_message' parameter in all versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-05-13
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows authenticated users with contributor privileges to embed arbitrary web scripts into the "permission_message" shortcode attribute of the Fluent Forms plugin. Because the input is neither sanitized nor properly escaped, the malicious code is stored in the database and executed whenever a user accesses a page containing the injected form, potentially enabling theft of credentials, cookie hijacking, or other malicious activities within the site context.

Affected Systems

All releases of the Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress by techjewel that are version 6.2.1 or earlier are impacted. Newer versions contain the fix and are therefore not affected.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity. No EPSS data is provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation at this time. However, the exploit requires a local authenticated attack via a contributor or higher role; an attacker who can edit forms can inject scripts that run in the browsers of any user who views the compromised form, compromising confidentiality and integrity of user sessions. The stored nature of the flaw means that the malicious payload remains until it is manually removed or the plugin is updated.

Generated by OpenCVE AI on May 13, 2026 at 05:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Fluent Forms to version 6.2.2 or later from the official source.
  • Verify that the "permission_message" field no longer accepts raw HTML by attempting to insert script tags in the form editor and confirming the input is sanitized or stripped.
  • As a temporary workaround, use custom code or a sanitization plugin to strip or escape the permission_message attribute, and restrict contributors and higher roles from editing form permissions.
  • Monitor site logs and user activity for unexpected form edits or script execution to detect potential exploitation.

Generated by OpenCVE AI on May 13, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 May 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Techjewel
Techjewel fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
Wordpress
Wordpress wordpress
Vendors & Products Techjewel
Techjewel fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
Wordpress
Wordpress wordpress

Wed, 13 May 2026 04:45:00 +0000

Type Values Removed Values Added
Description The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permission_message' parameter in all versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Fluent Forms <= 6.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'permission_message' Shortcode Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Techjewel Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-05-13T10:21:55.498Z

Reserved: 2026-04-21T20:57:55.395Z

Link: CVE-2026-6828

cve-icon Vulnrichment

Updated: 2026-05-13T10:18:45.790Z

cve-icon NVD

Status : Deferred

Published: 2026-05-13T05:16:24.077

Modified: 2026-05-13T14:43:46.717

Link: CVE-2026-6828

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T06:00:09Z

Weaknesses