What is CVE-2026-11881?
CVE-2026-11881 is a Stored Cross-Site Scripting (XSS) vulnerability in the Fluent Forms WordPress plugin before version 6.2.6. It occurs because a form field configuration setting is not sanitized and escaped before being output in an inline script, potentially allowing low-privileged users like Contributors with form-management permissions to inject malicious code. Immediate update to the latest patched version is required to mitigate the risk.
Azərbaycanca: CVE-2026-11881, Fluent Forms WordPress plaginində 6.2.6 versiyasından əvvəl mövcud olan zəiflikdir. Bu, form sahəsi konfiqurasiyasında təmizlənməmiş (sanitise) məlumatın istifadəsi nəticəsində yaranan Stored XSS boşluğudur. 'Contributor' kimi aşağı səviyyəli istifadəçilərə form idarəetmə icazəsi verildikdə, onların zərərli skript yerləşdirmə riski var; plaqin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
To which version should Fluent Forms be updated to mitigate the CVE-2026-11881 vulnerability?
To mitigate the CVE-2026-11881 vulnerability, the Fluent Forms plugin must be updated to version 6.2.6 or higher.
Which user role can potentially exploit the CVE-2026-11881 vulnerability?
This Stored XSS vulnerability can be exploited by low-privileged users such as Contributors who have been granted form-management permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.