Fluentforms develops a contact-form plugin for WordPress that, despite a narrow product scope, sits prominently in a widely deployed content-management ecosystem and attracts significant vulnerability attention. The vendor's disclosures skew toward serious outcomes and frequently acquire public exploit code; vulnerabilities recur through application-layer weakness classes including cross-site scripting, missing authorization, CSRF, improper authorization, and untrusted deserialization—all characteristic of form-handling and user-input processing in web plugins. Defenders should treat updates to this plugin as a priority given its prevalence and the direct attack surface it presents to unauthenticated visitors; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fluentforms over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2771CRITICAL The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability che | May 18, 2024 | 9.8 | 41 | NO | YES |
CVE-2024-2782HIGH The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c | May 18, 2024 | 7.5 | 32 | NO | YES |
CVE-2022-3463CRITICAL The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection | Nov 7, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-34620HIGH The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missi | Jul 7, 2021 | 8.8 | 28 | NO | NO |
CVE-2024-4157HIGH The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl | May 22, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-24410CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPManageNinja LLC Contact Form Plugin – Fastest Contact Form Bu | Oct 31, 2023 | 9.8 | 24 | NO | NO |
CVE-2024-10646MEDIUM The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject p | Dec 14, 2024 | 6.1 | 20 | NO | NO |
CVE-2024-4709MEDIUM The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parame | May 18, 2024 | 6.4 | 20 | NO | NO |
CVE-2023-0546MEDIUM The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in us | Apr 10, 2023 | 5.4 | 20 | NO | NO |
CVE-2024-9651MEDIUM The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site | Dec 9, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fluentforms.
Media articles that mention a CVE ID that affects a product developed by Fluentforms — matched by CVE ID, not by vendor name.