{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fluent-forms--6.2.11/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-18146"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Fluent Forms (\u003c= 6.2.11)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Fluent Forms"],"content_html":"\u003cp\u003eThe Fluent Forms - Customizable Contact Forms, Survey, Quiz, \u0026amp; Conversational Form Builder plugin for WordPress is affected by a stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-18146). The vulnerability stems from inadequate input sanitization and output escaping when processing Notification Smartcode values. Unauthenticated attackers can exploit this by submitting forms containing malicious payloads designed to be interpreted as Smartcodes. If an administrator or a user with entry-viewing permissions accesses the Submission Logs within the WordPress admin dashboard, the injected script executes in their browser session. This vulnerability impacts all versions of the plugin up to and including 6.2.11.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to the execution of arbitrary JavaScript within the administrative context of the WordPress dashboard. This can be used to perform actions on behalf of the administrator, such as creating new administrative accounts, modifying plugin configurations, or redirecting users to malicious sites, potentially leading to a full site compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Fluent Forms WordPress plugin to the latest version immediately to remediate CVE-2026-18146.\u003c/li\u003e\n\u003cli\u003eAudit WordPress administrative logs for unusual activity originating from the plugin's submission management interface.\u003c/li\u003e\n\u003cli\u003eReview all configured form notifications to identify potential misuse of Smartcode fields that may be reachable by unauthenticated form submitters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T08:54:48Z","date_published":"2026-08-13T08:54:48Z","id":"https://feed.craftedsignal.io/briefs/2026-08-fluent-forms-xss/","summary":"An unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Fluent Forms versions up to 6.2.11 allows attackers to inject malicious scripts that execute in the context of administrative users viewing submission logs.","title":"Stored XSS in Fluent Forms WordPress Plugin via Notification Smartcodes","url":"https://feed.craftedsignal.io/briefs/2026-08-fluent-forms-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Fluent Forms (\u003c= 6.2.11)","version":"https://jsonfeed.org/version/1.1"}