Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
FluentForm
Shahjahan Jewel
Developer
6.1.6
Latest version
600,000
Installations
6 days ago
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
20 fixed
7 Mitigation rules
Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read
5.1.16-6.1.1
Sep 2, 2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 6.0.2
Apr 17, 2025
IP-Spoofing vulnerability
<= 5.2.12
Mar 21, 2025
Unauthenticated Stored Cross-Site Scripting via Form Subject vulnerability
<= 5.2.6
Dec 13, 2024
Admin+ Stored XSS vulnerability
< 5.2.1
Dec 9, 2024
Authenticated (Form Manager+) Stored Cross-Site Scripting vulnerability
<= 5.1.19
Oct 7, 2024
Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification vulnerability
<= 5.1.18
Sep 3, 2024
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
<= 5.1.19
Jul 29, 2024
PHP Object Injection vulnerability
<= 5.1.15
May 23, 2024
Missing Authorization to Settings Update and Limited Privilege Escalation vulnerability
<= 5.1.16
May 20, 2024
Missing Authorization to Setting Manipulation vulnerability
<= 5.1.16
May 20, 2024
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
<= 5.1.13
May 20, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.1.16
May 20, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.1.9
Mar 6, 2024
Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title vulnerability
<= 5.1.5
Jan 19, 2024
Broken Access Control vulnerability
<= 5.0.8
Sep 11, 2023
SQL Injection vulnerability
<= 4.3.25
Jul 12, 2023
Contributor+ Stored XSS via Custom HTML Form Field vulnerability
< 4.3.25
Apr 11, 2023
CSV Injection vulnerability
<= 4.3.12
Oct 17, 2022
Cross-Site Request Forgery (CSRF) vulnerability leading to stored Cross-Site Scripting (XSS)
<= 3.6.65
Jun 16, 2021