CVE-2026-17571: The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in all v
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'param' in all versions up to, and including, 6.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-17571
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-17571 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Fluent Forms
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-17567: The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plu…nvd · 2026-07-31
- mediumCVE-2026-11881: The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form fi…nvd · 2026-07-30
- highCVE-2026-16655: The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plu…nvd · 2026-07-29
- highCVE-2026-15962: The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in…nvd · 2026-07-26
- mediumCVE-2026-5069: The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscri…nvd · 2026-07-10
- lowCVE-2026-11578: The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form…nvd · 2026-07-02
More from NVD Recent CVEs
- mediumCVE-2026-6453: The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to …2026-08-01
- mediumCVE-2026-18435: The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnera…2026-08-01
- mediumCVE-2026-18344: The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site …2026-08-01
- mediumCVE-2026-18062: The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnera…2026-08-01
- mediumCVE-2026-18059: The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to…2026-08-01