CVE-2026-6828

Basic Information

Severity MEDIUM
Base Score 6.4
CNA Wordfence
Published Date 2026-05-13 00:26:41 UTC
Last Modified 2026-05-13 06:21:55 UTC
CVE.org Link https://www.cve.org/CVERecord?id=CVE-2026-6828
NVD https://nvd.nist.gov/vuln/detail/CVE-2026-6828

Description

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permission_message' parameter in all versions up to, and including, 6.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affected Products

Vendor Product
techjewel fluent forms – customizable contact forms
techjewel quiz
techjewel survey
techjewel & conversational form builder