{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/wpmanageninja/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-16655"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Fluent Forms – Customizable Contact Forms, Survey, Quiz, \u0026 Conversational Form Builder (\u003c= 6.2.7)"],"_cs_severities":["high"],"_cs_tags":["wordpress","plugin","xss","vulnerability","webserver"],"_cs_type":"advisory","_cs_vendors":["wpmanageninja"],"content_html":"\u003cp\u003eA critical Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-16655, has been identified in the Fluent Forms - Customizable Contact Forms, Survey, Quiz, \u0026amp; Conversational Form Builder plugin for WordPress. This flaw impacts all plugin versions up to and including 6.2.7. The vulnerability stems from insufficient input sanitization and output escaping of data within the \u0026quot;Name Field Nested \u003ccode\u003epassword\u003c/code\u003e Member.\u0026quot; An unauthenticated attacker can leverage this weakness to inject malicious web scripts into web pages. When a legitimate user, such as an administrator, subsequently accesses these injected pages, the malicious scripts will execute within their browser context, potentially leading to session hijacking, sensitive data theft, or arbitrary actions on behalf of the victim. This vulnerability poses a significant risk to the integrity and security of WordPress sites utilizing the affected plugin.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a WordPress site running the vulnerable Fluent Forms plugin, version 6.2.7 or earlier.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious payload containing JavaScript code.\u003c/li\u003e\n\u003cli\u003eThe attacker submits this crafted payload into the \u0026quot;Name Field Nested \u003ccode\u003epassword\u003c/code\u003e Member\u0026quot; input of a Fluent Forms form on the target website.\u003c/li\u003e\n\u003cli\u003eDue to insufficient input sanitization and output escaping, the plugin stores the malicious script without properly neutralizing it.\u003c/li\u003e\n\u003cli\u003eThe malicious script becomes embedded within the website's database and rendered on web pages where the \u0026quot;Name Field Nested \u003ccode\u003epassword\u003c/code\u003e Member\u0026quot; content is displayed.\u003c/li\u003e\n\u003cli\u003eA legitimate user, such as a site administrator, accesses a page containing the maliciously injected content.\u003c/li\u003e\n\u003cli\u003eThe embedded script executes within the user's browser, allowing the attacker to perform actions like stealing session cookies, defacing the website, redirecting the user to malicious sites, or exfiltrating sensitive data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-16655 can lead to a severe compromise of the affected WordPress site and its users. An attacker can hijack user sessions, including those of administrators, gaining full control over the compromised accounts. This could result in unauthorized modification of website content, redirection of visitors to malicious sites, or the deployment of further client-side attacks. The vulnerability affects a widely used WordPress plugin, potentially exposing a broad range of websites to these risks. The CVSS v3.1 Base Score of 7.2 (High) reflects the significant security implications, particularly the potential for complete control over user sessions and client-side data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Fluent Forms - Customizable Contact Forms, Survey, Quiz, \u0026amp; Conversational Form Builder plugin to a version beyond 6.2.7 to patch CVE-2026-16655.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) to detect and block common XSS attack patterns in HTTP request bodies and parameters, providing a layer of defense against vulnerabilities like CVE-2026-16655.\u003c/li\u003e\n\u003cli\u003eEnsure server-side input validation and output encoding are rigorously applied for all user-supplied data in web applications to prevent similar Stored XSS vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T11:21:42Z","date_published":"2026-07-29T11:21:42Z","id":"https://feed.craftedsignal.io/briefs/2026-07-fluentforms-xss/","summary":"An unauthenticated attacker can exploit a Stored Cross-Site Scripting vulnerability (CVE-2026-16655) in the Fluent Forms WordPress plugin, versions up to and including 6.2.7, via insufficient input sanitization of the Name Field Nested `password` Member, allowing injection of arbitrary web scripts that execute in a user's browser upon page access.","title":"Fluent Forms WordPress Plugin Stored Cross-Site Scripting Vulnerability (CVE-2026-16655)","url":"https://feed.craftedsignal.io/briefs/2026-07-fluentforms-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Wpmanageninja","version":"https://jsonfeed.org/version/1.1"}