SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-11881

MEDIUM · CVSS 6.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Fluent Forms WordPress plugin prior to version 6.2.6 is vulnerable due to inadequate sanitization of form field configuration settings, which can lead to Stored Cross-Site Scripting (XSS) attacks. This flaw allows users with Contributor roles, who have delegated form-management permissions, to inject malicious scripts that execute in the browsers of visitors and administrators previewing the forms. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-11881
Severity
MEDIUM
CVSS
6.1
EPSS
0.18%
WordPress

Original NVD Description

The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it.