Executive brief
Forminator is a popular WordPress form builder plugin used to create contact forms, payment forms, and custom forms on websites. A flaw in how it processes Stripe payment API parameters allows attackers to inject malicious scripts into pages, which execute when users visit a link containing the payload. This could lead to account takeover, credential theft, or malware distribution on affected websites.
Technical details
The vulnerability is a DOM-based reflected cross-site scripting (XSS) flaw in the 'error_description' parameter used by the Stripe Checkout Sessions payment API integration. The plugin fails to properly sanitize and escape this parameter before rendering it in the DOM, allowing unauthenticated attackers to inject arbitrary JavaScript. The vulnerability is triggered only on pages hosting a Forminator form configured to use Stripe Checkout Sessions (the default since version 1.56.0). An attacker crafts a malicious URL containing XSS payload in the error_description parameter; when a user clicks the link, the script executes in their browser with the user's privileges. No patch version is publicly confirmed yet; users should upgrade from 1.57.0 or earlier.
Affected products
- WPMU DEV Forminator up to and including 1.57.0
Timeline
- 2026-08-25: disclosed