Sceawere

Vulnerability Detail

CVE-2026-66633UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Fluent Forms Pro XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
WPManageNinja
Product
Fluent Forms Pro Add On Pack
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-18T15:16:57.823Z",
  "pubdate": "2026-08-18T15:16:57.823Z",
  "executiveSummary": "An unauthenticated Cross-Site Scripting (XSS) vulnerability exists within the Fluent Forms Pro Add On Pack prior to version 6.2.12. This security flaw allows unauthenticated remote attackers to inject malicious client-side scripts, typically JavaScript, into web pages rendered to other users or administrators visiting the affected site.\nThe primary impact of this vulnerability involves the potential execution of arbitrary script code within the context of a victim's browser session. Depending on the target user's privileges, successful exploitation can lead to session hijacking, credential theft, unauthorized actions performed on behalf of the user, or defacement of the affected web application interface.\nThe affected product is the Fluent Forms Pro Add On Pack for WordPress, specifically targeting versions strictly less than 6.2.12. The risk implications are significant for organizations utilizing vulnerable iterations, as the flaw requires no prior authentication or specialized privileges to initiate an attack vector.\nAttackers require network access to the target web application to deliver the malicious payload. Exploitation prerequisites generally involve crafting a specialized input containing malicious script syntax that the vulnerable component fails to properly sanitize or encode before rendering it in the Document Object Model (DOM).",
  "technicalDetails": "The root cause of this vulnerability stems from insufficient input validation and output encoding within the Fluent Forms Pro Add On Pack component handling user-supplied data prior to rendering it in the application's response. Without rigorous context-aware sanitization, the application treats untrusted input as executable markup or script data.\nThe vulnerability is classified as an unauthenticated Cross-Site Scripting (XSS) issue affecting the Fluent Forms Pro Add On Pack for versions less than 6.2.12. Because the flaw is unauthenticated, threat actors do not need valid user credentials or elevated privilege requirements to interact with the vulnerable endpoint or input vector.\nThe network exposure is external, meaning any remote attacker with HTTP or HTTPS access to the web server hosting the vulnerable WordPress installation can attempt exploitation. The attack flow generally begins with the attacker crafting an HTTP request containing a malicious payload designed to bypass weak filtering mechanisms within the vulnerable component.\nUpon submission, the vulnerable Fluent Forms Pro Add On Pack processes the input and stores or reflects it without proper neutralization. When a victim or administrator subsequently triggers or views the affected application interface, the malicious payload is returned within the HTTP response and parsed by the browser.\nThe payload behavior involves the execution of arbitrary JavaScript within the security context of the victim's current browser session. This script can access Document objects, manipulate DOM elements, extract sensitive session cookies, or interact asynchronously with the server using the victim's authenticated privileges.\nPost-exploitation impact varies based on whether the targeted user holds administrative privileges. If an administrator views the malicious payload, the attacker may achieve full administrative compromise of the WordPress site by creating new administrative accounts, modifying core system configurations, or deploying further web shells."
}
CVE-2026-66633: Fluent Forms Pro XSS Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere