CVE-2026-18324
largeUnauthenticated Stored XSS in Forminator Forms WordPress Plugin
Forminator Forms, a WordPress plugin for building contact, payment, and custom forms, contains a stored cross-site scripting flaw (CWE-79) affecting every version up to and including 1.57.0.1, caused by insufficient input sanitization and output escaping of the Rich-Text Textarea field. An unauthenticated attacker can submit a form whose Textarea field has the Rich-Text editor option enabled and inject arbitrary web scripts that are stored with the submission. The injected scripts then execute in the browser of any user who accesses a page displaying the injected content, potentially enabling session or cookie theft, unauthorized admin actions, or content manipulation (CVSS scope-changed, low confidentiality and integrity impact). Any WordPress site running the plugin at version 1.57.0.1 or older, with at least one form using a Rich-Text-enabled Textarea field, is affected. No public proof-of-concept or in-the-wild exploitation is known; EPSS currently estimates only a 0.3% probability of exploitation within the next 30 days.
What to do: Update Forminator Forms to the latest available release (any version newer than 1.57.0.1). Until patched, audit all Forminator forms and disable the Rich-Text editor option on Textarea fields that accept public submissions, and review rendered pages for injected scripts. Sites that cannot update promptly should deactivate the plugin or take affected forms offline.
| WPMU DEV Forminator Forms – Contact Form, Payment Form & Custom Form Builder (WordPress plugin) | all versions up to and including 1.57.0.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the targeted Textarea field has the Rich-Text editor option enabled.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.