Executive brief
The Forminator Forms plugin is a popular WordPress form builder used to create contact forms, payment forms, and custom forms on websites. An unauthenticated attacker can inject malicious JavaScript code into forms that have rich-text editing enabled, which executes in the browsers of any user viewing the affected page. This could lead to session hijacking, credential theft, or defacement of the website.
Technical details
This is a Stored Cross-Site Scripting (XSS) vulnerability in the Rich-Text Textarea Field component of the Forminator plugin. The vulnerability stems from insufficient input sanitization and output escaping when processing user input in textarea fields with rich-text editor support. An unauthenticated attacker can craft malicious form submissions containing arbitrary JavaScript payloads that are stored in the database and executed in the context of any user's browser viewing the form or its entries. The vulnerability affects all versions up to and including 1.57.0.1, and exploitation requires that the target textarea field has the Rich-Text editor option explicitly enabled. A patch should be available in versions after 1.57.0.1.
Affected products
- Wpmudev Forminator up to and including 1.57.0.1
Timeline
- 2026-08-28: disclosed