Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows DOM-Based XSS.This issue affects Forminator: from n/a through <= 1.55.0.1.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Forminator plugin allows an attacker to inject malicious JavaScript into pages generated by the plugin because user input is not properly neutralized before being inserted into the DOM. This results in DOM‑based cross‑site scripting, giving the attacker the ability to run arbitrary scripts in the context of a visitor’s browser when that visitor loads a page containing a compromised form or data field.

Affected Systems

The flaw affects WPMU DEV – Your All‑in‑One WordPress Platform’s Forminator plugin. Versions through and including 1.55.0.1 are vulnerable, and any earlier release lacking a defined initial vulnerability date is also considered at risk.

Risk and Exploitability

The CVSS score of 7.1 reflect a high impact, while the EPSS score of less than 1% indicates that exploitation attempts are currently rare. The plugin is not listed in CISA’s KEV catalog, suggesting no large‑scale, publicly documented attacks. The likely exploitation path involves an attacker supplying crafted input via a user‑facing form or interface; the injected payload is then rendered in the victim’s browser, where it can execute within the user’s session scope.

Generated by OpenCVE AI on August 1, 2026 at 10:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Forminator version (greater than 1.55.0.1) to eliminate the XSS flaw.
  • If an upgrade cannot be performed immediately, disable or delete the Forminator plugin until the updated release is available.
  • Apply input validation measures or a content security policy on the site to mitigate the risk of malicious script execution while the plugin remains vulnerable.

Generated by OpenCVE AI on August 1, 2026 at 10:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpmu Dev - Your All-in-one Wordpress Platform
Wpmu Dev - Your All-in-one Wordpress Platform forminator
Vendors & Products Wordpress
Wordpress wordpress
Wpmu Dev - Your All-in-one Wordpress Platform
Wpmu Dev - Your All-in-one Wordpress Platform forminator

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows DOM-Based XSS.This issue affects Forminator: from n/a through <= 1.55.0.1.
Title WordPress Forminator plugin <= 1.55.0.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wpmu Dev - Your All-in-one Wordpress Platform Forminator
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:20:16.879Z

Reserved: 2026-06-25T08:05:16.224Z

Link: CVE-2026-57814

cve-icon Vulnrichment

Updated: 2026-07-13T14:20:12.242Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')