Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.5 WordPress CVE-2026-103353 CVE-2026-103343

Fluent Forms WordPress Plugin: Two Vulnerabilities Fixed in 6.2.15 (CVE-2026-103353, CVE-2026-103343)

Two vulnerabilities affecting FluentForm through version 6.2.14 have been disclosed: an unauthenticated flaw that can remove client-side functionality (CVE-2026-103353) and a stored cross-site scripting issue (CVE-2026-103343). Both are addressed in version 6.2.15.

Synthesized by AI from 4 sources · updated 1 hour ago

AI summary

Two security advisories have been published for Fluent Forms, a WordPress contact form plugin used on more than 700,000 sites. Both issues affect versions of FluentForm through 6.2.14 and are fixed in version 6.2.15. One vulnerability allows an unauthenticated actor to remove important client-side functionality, while the other is a stored cross-site scripting (XSS) flaw that requires some level of privilege and user interaction to exploit.

What happened

Two separate vulnerabilities were disclosed for the Fluent Forms WordPress plugin. CVE-2026-103353 is an Incorrect Behavior Order vulnerability (CWE-696) that allows an attacker to remove important client-side functionality. CVE-2026-103343 is a Stored Cross-Site Scripting vulnerability (CWE-79) caused by improper neutralization of input during web page generation. Both issues affect FluentForm through version 6.2.14.

Technical cause

CVE-2026-103353 stems from an incorrect order of operations in the plugin's logic (CWE-696), which can allow important client-side functionality to be disabled or removed. CVE-2026-103343 is a stored XSS vulnerability (CWE-79) resulting from insufficient sanitization or escaping of input that is later rendered in web pages generated by the plugin, allowing malicious script to be stored and later executed.

Who is affected

Any WordPress site running the Fluent Forms plugin (product name: Fluent Forms) at version 6.2.14 or earlier is affected by both vulnerabilities. The plugin is reported to be used on more than 700,000 WordPress installations.

Affected versions

Fluent Forms versions up to and including 6.2.14 are affected by both CVE-2026-103353 and CVE-2026-103343. The fixed version referenced in the advisories is 6.2.15.

Fixes and mitigation

The advisories list version 6.2.15 as the fixed version for both vulnerabilities. However, the fact package marks 'fix_available' as false for both CVEs, and no confirmed release or patch notes beyond the version number were supplied. Site owners should verify directly with the plugin changelog or vendor whether version 6.2.15 is actually published and addresses these issues before relying on it as a complete fix.

Recommended action

Check the installed version of Fluent Forms on your WordPress site. If you are running version 6.2.14 or earlier, monitor the vendor's official channels for confirmation and availability of version 6.2.15 or a later fixed release, and apply it as soon as it is verified. Until an update is confirmed and applied, consider restricting access to form-related functionality where feasible, especially for the unauthenticated issue (CVE-2026-103353).

PatchBriefing score

4.5 / 10 · Medium

Official CVSS: 5.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Why this score

CVE-2026-103353 has a CVSS base score of 5.3 (Medium), reflecting that it can be exploited by an unauthenticated attacker over the network without user interaction, but the impact is limited to removing client-side functionality with no confidentiality or availability impact at the server level. Its PatchBriefing score of 4.5 incorporates this base score along with factors for unauthenticated remote access, no required user interaction, the current lack of a confirmed fix, and the plugin's large install base. CVE-2026-103343 has a CVSS base score of 6.5 (Medium), reflecting a stored XSS issue that requires low-privilege access and user interaction, with limited confidentiality, integrity, and availability impact within the affected component. Its PatchBriefing score of 4.3 reflects this base score plus the lack of a confirmed fix and the plugin's popularity. Neither vulnerability is listed as known exploited or has a public exploit available.

Affected versions

Fluent Forms < 6.2.15
vulnerable
Fluent Forms < 6.2.15
vulnerable

Reported fixes

The advisories list version 6.2.15 as the fixed version for both vulnerabilities. However, the fact package marks 'fix_available' as false for both CVEs, and no confirmed release or patch notes beyond the version number were supplied. Site owners should verify directly with the plugin changelog or vendor whether version 6.2.15 is actually published and addresses these issues before relying on it as a complete fix.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • WPVulnerability database
  • NVD (NIST) database
  • WPVulnerability database
  • NVD (NIST) database
Unified report
Fluent Forms WordPress Plugin: Two Vulnerabilities Fixed in 6.2.15 (CVE-2026-103353, CVE-2026-103343)
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email