What is CVE-2026-16655?
CVE-2026-16655 is a Stored Cross-Site Scripting vulnerability in the Fluent Forms plugin for WordPress. It exists in all versions up to 6.2.7 due to insufficient input sanitization and output escaping within the nested `password` member of the Name Field. Users should update the plugin immediately to mitigate the risk.
Azərbaycanca: CVE-2026-16655, WordPress üçün Fluent Forms plaginində saxlanılan XSS zəifliyidir. "Name" sahəsindəki iç-içə `password` üzvü vasitəsilə təcavüzkar zərərli skript yerləşdirə bilər. Plaginin 6.2.7 və daha əvvəlki versiyaları təsirlənir, istifadəçilərə dərhal yeniləmə və ya giriş təmizləmə tədbirləri görmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Fluent Forms plugin are affected by CVE-2026-16655?
This stored XSS vulnerability affects all versions of the Fluent Forms plugin up to and including 6.2.7.
Where can an attacker inject the malicious script in the CVE-2026-16655 exploit?
The attacker can inject a malicious script via the nested `password` member within the Name Field.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.