The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in the browser of an administrator (or any user with the Fluent Forms entry-viewing capability) when they view the form's entry Submission Logs in the WordPress admin dashboard. Exploitation requires that a site administrator or Fluent Forms manager has configured an email notification whose subject or static (direct) Send To value references an attacker-influenced Smartcode such as an input_password field value, a cookie value, or submission.response.
We have discovered 97,501 live websites that are affected by CVE-2026-18146.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 97,501 live websites (100% of Fluentform install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 110 versions ( 100% of all versions) |
| 30,050 websites | |
| 10,207 websites | |
| 5,860 websites | |
| 4,732 websites | |
| 3,647 websites | |
| 2,566 websites | |
| 2,545 websites | |
| 2,507 websites | |
| 2,376 websites | |
| 2,172 websites |
| .com | 41,918 websites |
| .de | 6,161 websites |
| .org | 4,457 websites |
| .co.uk | 3,473 websites |
| .nl | 3,312 websites |
| .com.au | 2,384 websites |
| .fr | 2,168 websites |
| .it | 1,856 websites |
| .net | 1,840 websites |
| .com.br | 1,776 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.***.ca | *,*** | ||
| **********.com | *,*** | ||
| ********.com | *,*** | ||
| ***************.com | *,*** | ||
| *****************.com | *,*** | ||
| ********************.com | **,*** | ||
| ********.com | **,*** | ||
| *********************.fr | **,*** | ||
| ************.vn | **,*** | ||
| **********************.org | **,*** |
FAQ