CVE: CVE-2026-0996 CVSS: 6.4 (Medium) Publicly Published: February 9, 2026 Last Updated: February 10, 2026 Researcher: Osvaldo Noe Gonzalez Del Rio (Os) - cyberdogzmarketing.com Vulnerability Description: - Description: Fluent Forms <= 6.1.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module. An Authenticated (Subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Fluent Forms plugin in versions up to and including 6.1.14 is vulnerable to a cross-site scripting attack that allows authenticated attackers with Subscriber-level access and above to inject arbitrary web scripts that will execute in the context of any user accessing the form. Vulnerability Details for Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder: - Software Type: Plugin - Software Slug: fluentform - Patched?: Yes - Remediation: Update to version 6.1.15, or a newer patched version - Affected Version: <= 6.1.14 - Patched Version: 6.1.15 References - plugins.trac.wordpress.org - plugins.trac.wordpress.org - plugins.trac.wordpress.org - plugins.trac.wordpress.org - plugins.trac.wordpress.org