A vulnerability was found in wpmanageninja Fluent Forms Plugin up to 6.2.11 on WordPress and classified as problematic . Affected is an unknown function of the component Notification Smartcode . Executing a manipulation can lead to cross site scripting. The identification of this vulnerability is CVE-2026-18146 . The attack may be launched remotely. There is no exploit available.