Junglewise Threat Intelligence

CVE-2026-57814: WPMU DEV Forminator DOM-based XSS

CVE-2026-57814 · Severity: high · CVSS 7.1 · Published 2026-07-13

Technologies: WPMU DEV Forminator. Vendors: WPMU DEV.

Executive brief

Forminator, a popular WordPress plugin used for creating forms, polls, and quizzes, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could execute code in their browser, potentially leading to unauthorized actions, data theft, or website defacement. This vulnerability is particularly dangerous as it can be used in automated campaigns targeting many websites simultaneously.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the WPMU DEV Forminator plugin for WordPress (versions <= 1.55.0.1). The flaw stems from improper neutralization of user-supplied input during web page generation, specifically within the DOM environment. An unauthenticated remote attacker can exploit this by tricking a user into performing an action, such as clicking a malicious link. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized administrative actions. The issue is resolved in version 1.55.0.2.

Affected products

  • WPMU DEV Forminator <= 1.55.0.1

Timeline

  • 2026-06-22: disclosed: Reported by daroo
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: advisory: NVD published date

References

Related threats