Sceawere
Vulnerability Detail
CVE-2026-94675UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Fluent Forms Pro Unauthenticated XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- Fluent Forms Free vs Pro
- Product
- Fluent Forms Pro Add On Pack
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:57.047Z",
"pubdate": "2026-10-06T09:17:57.047Z",
"executiveSummary": "This vulnerability is an Unauthenticated Stored or Reflected Cross-Site Scripting (XSS) flaw identified within the Fluent Forms Pro Add On Pack, specifically affecting all versions up to and including 6.2.13.\nThe vulnerability permits an unauthenticated attacker to inject and execute arbitrary malicious JavaScript within the context of a victim's browser session. By bypassing authentication requirements, an attacker can target administrative or user sessions without prior access to the application.\nSuccessful exploitation poses a significant security risk, as it enables session hijacking, credential theft, redirection to malicious domains, and unauthorized modification of the Document Object Model (DOM).\nThe vulnerability stems from improper neutralization of user-supplied input before it is reflected or stored by the application. Because the entry point does not require authentication, the attack surface is wide, potentially allowing remote exploitation via public-facing forms or endpoints.\nOrganizations utilizing the Fluent Forms Pro Add On Pack are at risk of data breach and site compromise if the vulnerable code remains accessible.",
"technicalDetails": "The root cause of this vulnerability lies in the failure of the Fluent Forms Pro Add On Pack to adequately sanitize or escape user-controlled input prior to processing it within the application logic or rendering it in the browser.\nIn versions 6.2.13 and earlier, the plugin fails to implement sufficient output encoding or input validation on specific parameters processed during form handling or data submission workflows. This allows an attacker to inject crafted JavaScript payloads into the application.\nThe attack flow begins when an unauthenticated attacker identifies a vulnerable endpoint within the Fluent Forms Pro Add On Pack. By submitting specially crafted input containing malicious HTML tags or script blocks (e.g., <script>alert(document.cookie)</script>), the attacker forces the application to store or reflect the payload.\nWhen a legitimate user, such as an administrator, views the affected component—such as a form entry dashboard, submission logs, or a generated report—the browser interprets the injected payload as trusted code. This executes the malicious script in the security context of the victim's session.\nThe lack of authentication requirements facilitates remote exploitation, as the attacker does not need legitimate credentials to interact with the vulnerable endpoint. The browser executes the payload automatically when the victim interacts with the compromised UI elements, demonstrating a classic XSS attack vector.\nPost-exploitation, the attacker may perform unauthorized actions on behalf of the victim. This includes stealing sensitive session cookies, capturing form data, exfiltrating CSRF tokens, or deploying secondary payloads to perform further reconnaissance or privilege escalation within the WordPress installation.\nThe vulnerability persists because the affected components fail to adhere to secure coding practices regarding input handling and output encoding, specifically failing to utilize WordPress security APIs like esc_html(), esc_attr(), or wp_kses() consistently across all data input and rendering paths.\nThe network exposure is global, as the affected forms are typically accessible via standard web protocols (HTTP/HTTPS) on the public-facing side of the website, requiring only knowledge of the specific vulnerable parameter or form path to initiate the exploit."
}