Description
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
Published: 2026-08-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated Cross Site Scripting flaw in the Forminator plugin for WordPress versions up to 1.56.0. Because input is not properly sanitized, an attacker can inject malicious script that executes in the context of the website visitor’s browser. This can lead to session hijacking, defacement, theft of sensitive information, or redirecting the user to phishing sites. The weakness is a classic input validation problem classified as CWE‑79.

Affected Systems

All WordPress sites that have the WPMU DEV Forminator plugin installed with a version that is 1.56.0 or older are affected. No other vendors or products are listed in the CNA data.

Risk and Exploitability

With a CVSS score of 7.1, the risk is considered high. No EPSS information is available and the vulnerability is not listed in CISA’s KEV catalog, but the attack does not require authentication and can be triggered from any user who visits a page containing a vulnerable form. An attacker can craft a malicious form solution URL that, when opened, will execute the injected code in the visitor’s browser.

Generated by OpenCVE AI on August 6, 2026 at 15:27 UTC.

Remediation

Vendor Solution

Update the WordPress Forminator plugin to the latest available version (at least 1.56.1).


OpenCVE Recommended Actions

  • Update the Forminator plugin to version 1.56.1 or later
  • If an immediate update is not possible, disable or remove the Forminator plugin from the site to prevent exploitation
  • Configure the server to enforce strict Content Security Policy headers to mitigate XSS effects on a broader range of sites if disabling the plugin is not feasible

Generated by OpenCVE AI on August 6, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
Title WordPress Forminator plugin <= 1.56.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:11.872Z

Reserved: 2026-02-25T12:14:24.000Z

Link: CVE-2026-28143

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T15:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')