The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline script when a form is rendered, which could allow users with a role as low as Contributor (with delegated form-management permission, and therefore lacking the unfiltered_html capability, e.g. in a multisite setup) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who loads the form, including administrators previewing it.
We have discovered 96,122 live websites that are affected by CVE-2026-11881.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 96,122 live websites (100% of Fluentform install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 105 versions ( 100% of all versions) |
| 30,034 websites | |
| 10,013 websites | |
| 5,779 websites | |
| 4,667 websites | |
| 3,506 websites | |
| 2,539 websites | |
| 2,522 websites | |
| 2,403 websites | |
| 2,333 websites | |
| 2,094 websites |
| .com | 41,402 websites |
| .de | 5,998 websites |
| .org | 4,428 websites |
| .co.uk | 3,457 websites |
| .nl | 3,180 websites |
| .com.au | 2,374 websites |
| .fr | 2,140 websites |
| .net | 1,862 websites |
| .it | 1,769 websites |
| .com.br | 1,755 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.***.ca | *,*** | ||
| **********.com | *,*** | ||
| ********.com | *,*** | ||
| ***************.com | *,*** | ||
| *****************.com | *,*** | ||
| ********************.com | **,*** | ||
| ********.com | **,*** | ||
| *********************.fr | **,*** | ||
| ************.vn | **,*** | ||
| **********************.org | **,*** |
FAQ