Impact
The Forminator Forms plugin for WordPress is vulnerable to a stored cross‑site scripting flaw in any Rich‑Text Textarea field. An unauthenticated attacker can place malicious JavaScript code that is saved as part of a form submission. When an administrator later opens the stored entry from the Forminator Entries view, the script is executed in the context of their authenticated wp‑admin session by WordPress core’s jQuery click handler on .contextual‑help‑tabs a. This allows the attacker to run arbitrary code with the privileges of the administrator, potentially compromising the entire WordPress installation.
Affected Systems
This issue affects the Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin maintained by WPMU DEV. All releases up to and including version 1.57.2 are impacted. The vulnerability exists regardless of the WordPress core version, as it relies on the plugin’s input handling and WordPress output routines.
Risk and Exploitability
The CVSS score of 7.2 indicates moderate to high severity, with the attack vector relying on an unauthenticated user injecting data into a form that is later displayed to an administrator. Although the attack requires the admin to interact with the stored entry, the risk remains significant because many administrators routinely review entries. The EPSS score is not available, and the vulnerability has not yet been listed in the CISA KEV catalog, but the lack of a deterrent and the potential impact justify proactive remediation.
OpenCVE Enrichment