Vulnerabilities and security researches forfluent-crm fluent-crm
Direction: descendingMay 23, 2026
Email Marketing, Newsletter, Email Automation and CRM Plugin for WordPress by FluentCRM # CVE-2026-7798
- CVE, Research URL
- Home page URL
- Date
- -
- Research Description
- FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 3.0.0 CVE-2026-7798
- Affected versions
-
max 3.0.0.
- Status
-
vulnerable
Dec 11, 2025
Email Marketing, Newsletter, Email Automation and CRM Plugin for WordPress by FluentCRM # CVE-2025-12935
- CVE, Research URL
- Home page URL
- Date
- Nov 21, 2025
- Research Description
- The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fluentcrm_content' shortcode in all versions up to, and including, 2.9.84 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 2.9.85.
- Status
-
vulnerable
Jun 07, 2024
Email Marketing, Newsletter, Email Automation and CRM Plugin for WordPress by FluentCRM # CVE-2023-1430
- CVE, Research URL
- Home page URL
- Date
- Jun 09, 2023
- Research Description
- The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.7.40 due to the use of an MD5 hash without a salt to control subscriptions. This makes it possible for unauthenticated attackers to unsubscribe users from lists and manage subscriptions, granted they gain access to any targeted subscribers email address.
- Affected versions
-
max 2.8.02.
- Status
-
vulnerable
Email Marketing, Newsletter, Email Automation and CRM Plugin for WordPress by FluentCRM # CVE-2024-30430
- CVE, Research URL
- Home page URL
- Date
- Mar 29, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Email Newsletter Team - FluentCRM Fluent CRM allows Stored XSS.This issue affects Fluent CRM: from n/a through 2.8.44.
- Affected versions
-
max 2.8.45.
- Status
-
vulnerable