An unauthenticated attacker can exploit a Stored Cross-Site Scripting vulnerability (CVE-2026-16655) in the Fluent Forms WordPress plugin, versions up to and including 6.2.7, via insufficient input sanitization of the Name Field Nested `password` Member, allowing injection of arbitrary web scripts that execute in a user's browser upon page access.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
wordpress
plugin
xss
vulnerability
webserver
2t
1c