Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw in the Forminator plugin for WordPress versions up to 1.56.0. Because input is not properly sanitized, an attacker can inject malicious script that executes in the context of the website visitor’s browser. This can lead to session hijacking, defacement, theft of sensitive information, or redirecting the user to phishing sites. The weakness is a classic input validation problem classified as CWE‑79.
Affected Systems
All WordPress sites that have the WPMU DEV Forminator plugin installed with a version that is 1.56.0 or older are affected. No other vendors or products are listed in the CNA data.
Risk and Exploitability
With a CVSS score of 7.1, the risk is considered high. No EPSS information is available and the vulnerability is not listed in CISA’s KEV catalog, but the attack does not require authentication and can be triggered from any user who visits a page containing a vulnerable form. An attacker can craft a malicious form solution URL that, when opened, will execute the injected code in the visitor’s browser.
OpenCVE Enrichment