Extension WordPress
Vulnérabilités Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
Cette page rassemble les failles publiées pour Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
34 fiches
Fluent Forms <= 6.2.1 – Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id'
The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes…
*-6.2.1
6.2.2
09/07/2026
Fluent Forms <= 6.2.0 – Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.0 via the exportEntries function due to missing…
*-6.2.0
6.2.1
13/05/2026
Fluent Forms <= 6.1.21 – Authenticated (Subscriber+) Authorization Bypass via 'form_id' Parameter
The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authorizing submission-level actions (read, modify, delete, add notes) based…
*-6.1.21
6.2.0
13/05/2026
Fluent Forms <= 6.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'permission_message' Shortcode Attribute
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permission_message' parameter in all versions up to, and including, 6.2.1 due to insufficient input…
*-6.2.1
6.2.2
12/05/2026
Fluent Forms <= 6.2.1 – Authenticated (Administrator+) Arbitrary File Read via Path Traversal in Email Attachment
The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attacker-supplied file-upload URLs into…
*-6.2.1
6.2.2
05/05/2026
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 – Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in versions up to, and including, 6.1.21. This is due to…
6.1.21
6.2.0
16/04/2026
Fluent Forms <= 6.1.14 – Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module
The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all versions up to, and including, 6.1.14 due to a combination of missing authorization checks, a leaked nonce, and…
*-6.1.14
6.1.15
09/02/2026
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.14 – Missing Authorization
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.1.14.…
*-6.1.14
6.1.15
25/01/2026
FluentForm <= 6.1.11 – Unauthenticated Arbitrary Shortcode Execution
The The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.1.11. This is due to the software allowing…
*-6.1.11
6.1.12
13/01/2026
Fluent Forms <= 6.1.7 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the…
*-6.1.7
6.1.8
06/01/2026
Fluent Forms <= 6.1.7 – Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.1.7 via the 'submission_id' parameter due to missing…
*-6.1.7
6.1.8
05/12/2025
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 – 6.1.1 – Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes…
5.1.16-6.1.1
6.1.2
02/09/2025
Fluent Forms <= 6.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-6.0.2
6.0.3
16/04/2025
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 – IP-Spoofing
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use…
*-5.2.12
6.0.0
21/03/2025
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.2.6 – Unauthenticated Stored Cross-Site Scripting via Form Subject
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in all versions up to, and including,…
*-5.2.6
5.2.7
13/12/2024
Fluent Forms <= 5.2.0 – Authenticated (Admin+) Stored Cross-Site Scripting
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.2.0 due to insufficient input sanitization…
*-5.2.0
5.2.1
18/11/2024
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 – Authenticated (Form Manager+) Stored Cross-Site Scripting
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form label fields in all versions up to, and including, 5.1.19…
*-5.1.19
5.1.20
04/10/2024
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 – Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function…
*-5.1.18
5.1.19
31/08/2024
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom error message in all versions up to, and including, 5.1.19…
*-5.1.19
5.1.20
27/07/2024
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via input fields in all versions up to, and including, 5.1.19 due…
*-5.1.19
5.1.20
27/07/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.