<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Fluent Forms (&lt;= 6.2.11) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/fluent-forms--6.2.11/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 13 Aug 2026 08:54:48 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/fluent-forms--6.2.11/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Fluent Forms WordPress Plugin via Notification Smartcodes</title><link>https://feed.craftedsignal.io/briefs/2026-08-fluent-forms-xss/</link><pubDate>Thu, 13 Aug 2026 08:54:48 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-fluent-forms-xss/</guid><description>An unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Fluent Forms versions up to 6.2.11 allows attackers to inject malicious scripts that execute in the context of administrative users viewing submission logs.</description><content:encoded><![CDATA[<p>The Fluent Forms - Customizable Contact Forms, Survey, Quiz, &amp; Conversational Form Builder plugin for WordPress is affected by a stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-18146). The vulnerability stems from inadequate input sanitization and output escaping when processing Notification Smartcode values. Unauthenticated attackers can exploit this by submitting forms containing malicious payloads designed to be interpreted as Smartcodes. If an administrator or a user with entry-viewing permissions accesses the Submission Logs within the WordPress admin dashboard, the injected script executes in their browser session. This vulnerability impacts all versions of the plugin up to and including 6.2.11.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to the execution of arbitrary JavaScript within the administrative context of the WordPress dashboard. This can be used to perform actions on behalf of the administrator, such as creating new administrative accounts, modifying plugin configurations, or redirecting users to malicious sites, potentially leading to a full site compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Fluent Forms WordPress plugin to the latest version immediately to remediate CVE-2026-18146.</li>
<li>Audit WordPress administrative logs for unusual activity originating from the plugin's submission management interface.</li>
<li>Review all configured form notifications to identify potential misuse of Smartcode fields that may be reachable by unauthenticated form submitters.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>