← All articles Security

Fluent Forms CVE-2026-16655: Update to 6.2.8 Now

If your site runs Fluent Forms and the plugin is below version 6.2.8, an attacker can exploit a confirmed vulnerability to manipulate or extract data from

Published Jason Boyd

If your site runs Fluent Forms and the plugin is below version 6.2.8, an attacker can exploit a confirmed vulnerability to manipulate or extract data from your site without needing administrative credentials. The CVE record published 29 July 2026 scores this at 7.2 out of 10 on the CVSS scale, placing it firmly in the High severity band, and that score reflects real, material risk to any site running an affected version.

Fluent Forms is widely used for contact forms, surveys, quizzes, and multi-step conversational forms. If you collect enquiries, run lead generation forms, or gather customer feedback through your WordPress site, there is a reasonable chance this plugin is active on your installation right now.

What the Vulnerability Allows and Who Is Exposed

A CVSS score of 7.2 in the High band means exploitation requires no administrative account. The vulnerability affects all versions below 6.2.8, so any site that has not updated since the fix was released on 29 July 2026 remains exposed.

For a business owner, the practical consequence is straightforward: form submissions flowing through your site, which may include names, email addresses, phone numbers, and any other data your forms collect, are accessible to an unauthorised third party. If your forms feed into a CRM, a payment workflow, or a mailing list, the exposure extends beyond the WordPress site itself.

High-severity plugin flaws at this CVSS range are precisely what automated scanning tools look for continuously. Attackers do not target your site specifically — they scan large numbers of WordPress installations, identify outdated plugin versions, and act on the results. A site running Fluent Forms below 6.2.8 is visible to those scans, and the vulnerability type makes it a reliable target.

How to Check Your Version and Apply the Fix

Checking your current Fluent Forms version takes under two minutes. Log into your WordPress dashboard and go to Plugins > Installed Plugins, then search for “Fluent Forms” in the plugin list. The version number appears beneath the plugin name. If it reads anything below 6.2.8, the site is vulnerable and the update is overdue.

To update, click Update Now directly from that screen, or go to Dashboard > Updates to see all pending plugin updates at once. The fix is available in version 6.2.8 and any subsequent release. Once the update completes, confirm the version number has changed in the Installed Plugins list.

Before updating, take a backup of your site. Most managed hosting environments run daily backups, but confirm yours has completed a recent snapshot before applying any plugin update — a backup takes minutes to verify and removes the only sensible reason to hesitate. If your site is managed through a staging environment or a deployment pipeline, that process should not delay the update beyond today.

After updating, test your forms by submitting a test entry through each active form on the site and confirming the data reaches its destination correctly. Fluent Forms 6.2.8 is a security release, but any plugin update warrants a brief functional check.

One point that business owners often overlook: if your WordPress site has multiple administrators or editors, any one of them can update plugins. If you rely on a developer or agency to handle updates, send them this post directly and ask for written confirmation that the update has been applied.

Plugin updates are the single most common remediation step in WordPress security advisories, and they are also the most commonly deferred — usually because site owners worry that an update will break something. That concern is legitimate for major version changes, but a security patch on a well-maintained plugin carries far less risk than leaving a known High-severity vulnerability in place. The question is how quickly, not whether.

The broader pattern is worth naming plainly. WordPress powers a large share of the web precisely because its plugin architecture lets site owners add almost any functionality without writing code, but that same architecture means third-party code runs with significant access to your site’s database, files, and user data. A plugin installed two years ago and left unattended is an entry point that may have accumulated unpatched vulnerabilities since installation. Every week that passes between a CVE disclosure and an applied update is a week during which that attack vector remains open, and for a High-severity vulnerability scored at 7.2, that window should be measured in hours.

Keeping plugins updated is the primary mechanism by which known attack vectors are closed. If you collect any personal data through your forms, including names, email addresses, or enquiry details, you also carry a legal obligation under UK GDPR to take reasonable steps to protect that data, and leaving a patched vulnerability unaddressed on a site that processes personal data is not a position most business owners would choose to defend.


If you run Fluent Forms and want confirmation that version 6.2.8 has been applied correctly and your site is not carrying other unpatched plugin vulnerabilities, I offer a focused WordPress security audit through The WordPress Guy. Given that this CVE was disclosed on 29 July 2026 and automated scanners are already indexing affected sites, the time to act is now. Book a security audit and I will check your plugin versions, identify any other outstanding vulnerabilities, and give you a clear remediation list.

Related articles

All articles →

Security issues need permanent fixes, not surface-level patches. This is exactly the work I specialise in.

View security services →
Jason Boyd

Jason Boyd

Specialist WordPress Engineer · Former W3C Invited Expert · 20+ years

I fix the WordPress problems other developers walk away from. Backed by a 1st Class degree in Computer Science, an MSc in Cybersecurity, and over 20 years of specialist WordPress work, I diagnose issues at their root cause and resolve them permanently — for businesses that cannot afford guesswork or repeat failures.

Need hands-on help?

If this article describes your situation, I can diagnose the specifics and fix it properly. Send your brief and I'll respond the same working day.