Impact
The Forminator Forms plugin stores user‑input from Rich‑Text textarea fields without adequate sanitization or output escaping, allowing an unauthenticated attacker to embed malicious JavaScript that executes whenever a page displaying that entry is viewed. This plug‑in flaw can deface the site, steal session cookies, or perform other client‑side attacks against any visitor.
Affected Systems
The vulnerability applies to the Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress released by wpmudev. All releases up to and including version 1.57.0.1 are affected. Users running any of these versions should verify whether Rich‑Text editing is enabled in any textarea field.
Risk and Exploitability
The reported CVSS score is 7.2, indicating a high impact when combined with sufficient exploitation difficulty. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector requires an unauthenticated user to submit malicious content via a Rich‑Text‑enabled textarea, which the plugin then stores and later renders without filtering. Because the flaw is web‑based with no authentication requirement, it is potentially exploitable on any public installation that allows form entry.
OpenCVE Enrichment