Impact
The vulnerability in the Forminator plugin allows an attacker to inject malicious JavaScript into pages generated by the plugin because user input is not properly neutralized before being inserted into the DOM. This results in DOM‑based cross‑site scripting, giving the attacker the ability to run arbitrary scripts in the context of a visitor’s browser when that visitor loads a page containing a compromised form or data field.
Affected Systems
The flaw affects WPMU DEV – Your All‑in‑One WordPress Platform’s Forminator plugin. Versions through and including 1.55.0.1 are vulnerable, and any earlier release lacking a defined initial vulnerability date is also considered at risk.
Risk and Exploitability
The CVSS score of 7.1 reflect a high impact, while the EPSS score of less than 1% indicates that exploitation attempts are currently rare. The plugin is not listed in CISA’s KEV catalog, suggesting no large‑scale, publicly documented attacks. The likely exploitation path involves an attacker supplying crafted input via a user‑facing form or interface; the injected payload is then rendered in the victim’s browser, where it can execute within the user’s session scope.
OpenCVE Enrichment