Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.0 WordPress CVE-2026-101324

CVE-2026-101324 — Fluent Forms reflected XSS via {get.*} in Custom HTML fields

Fluent Forms contains a reflected cross-site scripting (XSS) issue where unauthenticated input via {get.*} SmartCodes in Custom HTML fields can inject script; the issue is addressed in 6.2.15. [CVE-2026-101324]

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

This advisory covers CVE-2026-101324, a reflected cross-site scripting (CWE-79) vulnerability in the Fluent Forms WordPress plugin that can allow injection of attacker-controlled script when certain SmartCodes are used inside URL attributes in Custom HTML fields. The advisory data notes a fixed version of 6.2.15. (Sources: WPVulnerability, NVD.)

What happened

Fluent Forms contains a reflected cross-site scripting vulnerability that can be triggered by an attacker-controlled value supplied to a {get.NAME} (described generally as {get.*}) SmartCode used inside a URL-accepting attribute (for example an iframe src or an a href) within a published Custom HTML field. If a user is tricked into performing an action such as clicking a crafted link, injected script can execute in that user's browser. (Source IDs: 8619, 32388)

Technical cause

The root cause reported is insufficient input sanitization and output escaping for attacker-controlled values expanded by {get.*} SmartCodes when placed inside URL-accepting attributes in Custom HTML fields. This allows reflected script to be returned and executed in a user's browser when the crafted input is returned in the page context. (Source IDs: 8619, 32388)

Why it matters

An unauthenticated actor can supply the attacker-controlled value used by the SmartCode; successful exploitation relies on tricking a user into activating the crafted input (for example by clicking a link). The CVSS v3.1 base score is 4.7 (vector: AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N), indicating a network-reachable issue that requires user interaction and yields limited confidentiality and integrity impact but a scope change. (Source IDs: 8619, 32388)

Who is affected

Sites using the Fluent Forms WordPress plugin with the vulnerable range (versions up to and including 6.2.14) are affected if an administrator has published a form containing a Custom HTML field that uses a {get.*} SmartCode inside a URL-accepting attribute. Not all Fluent Forms installations are affected — the site must have that specific configuration. (Source IDs: 8619, 32388)

Discovery and timeline

The advisory records publication on 2026-10-09 and an update on 2026-10-10 in the source records. The NVD and WPVulnerability entries list the vulnerability as CVE-2026-101324. The available metadata indicates there is no public exploit and it is not marked as known exploited. The advisory data does not provide information about an individual discoverer or a vendor statement. (Source IDs: 8619, 32388)

Affected versions

The advisory identifies affected versions as up to and including 6.2.14, and reports a fix in 6.2.15. (Source IDs: 8619, 32388)

Fixes and mitigation

Package metadata reports a fixed release of the Fluent Forms plugin in 6.2.15 (see source). However, the advisory record also includes a field that indicates 'fix_available' is false. These two facts conflict. If 6.2.15 is available to you, update to 6.2.15. As an immediate mitigation, review published forms for Custom HTML fields that embed {get.*} SmartCodes inside URL-accepting attributes and remove or disable those fields where possible. (Source IDs: 8619, 32388)

Recommended action

1) If you can obtain the 6.2.15 update from your plugin source, apply it. 2) Audit published forms for Custom HTML fields that use {get.*} SmartCodes inside URL-accepting attributes and remove or alter those fields to avoid expanding untrusted input into URL attributes. 3) Review administrator privileges and restrict who can publish or edit Custom HTML fields. Verify changes on a staging site before applying to production. (Source IDs: 8619, 32388)

PatchBriefing score

4.0 / 10 · Medium

Official CVSS: 4.7

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

Why this score

The CVSS v3.1 base score is 4.7 (vector AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N), as recorded in the advisory metadata. This reflects a network-reachable vulnerability that requires user interaction and high attack complexity, with limited confidentiality and integrity impact and no availability impact; scope is reported to change. The patchwire score is 4, calculated from the advisory's factors including unauthenticated remote exploitability and a reported fix indicator; see source records for factor details. (Source IDs: 8619, 32388)

Affected versions

Fluent Forms < 6.2.15
vulnerable

Reported fixes

Package metadata reports a fixed release of the Fluent Forms plugin in 6.2.15 (see source). However, the advisory record also includes a field that indicates 'fix_available' is false. These two facts conflict. If 6.2.15 is available to you, update to 6.2.15. As an immediate mitigation, review published forms for Custom HTML fields that embed {get.*} SmartCodes inside URL-accepting attributes and remove or disable those fields where possible. (Source IDs: 8619, 32388)

How this was built

2 source records were collected, matched and used to prepare the report above.

  • WPVulnerability database
  • NVD (NIST) database
Unified report
CVE-2026-101324 — Fluent Forms reflected XSS via {get.*} in Custom HTML fields
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email