Description
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to open the stored submission entry in the Forminator Entries view and interact with the planted link, at which point WordPress core's jQuery-based click handler on `.contextual-help-tabs a` evaluates the entity-decoded href as HTML, firing the attacker's payload in the administrator's authenticated wp-admin session.
Published: 2026-10-01
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting that can execute arbitrary scripts in an authenticated admin session
Action: Apply Patch
AI Analysis

Impact

The Forminator Forms plugin for WordPress is vulnerable to a stored cross‑site scripting flaw in any Rich‑Text Textarea field. An unauthenticated attacker can place malicious JavaScript code that is saved as part of a form submission. When an administrator later opens the stored entry from the Forminator Entries view, the script is executed in the context of their authenticated wp‑admin session by WordPress core’s jQuery click handler on .contextual‑help‑tabs a. This allows the attacker to run arbitrary code with the privileges of the administrator, potentially compromising the entire WordPress installation.

Affected Systems

This issue affects the Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin maintained by WPMU DEV. All releases up to and including version 1.57.2 are impacted. The vulnerability exists regardless of the WordPress core version, as it relies on the plugin’s input handling and WordPress output routines.

Risk and Exploitability

The CVSS score of 7.2 indicates moderate to high severity, with the attack vector relying on an unauthenticated user injecting data into a form that is later displayed to an administrator. Although the attack requires the admin to interact with the stored entry, the risk remains significant because many administrators routinely review entries. The EPSS score is not available, and the vulnerability has not yet been listed in the CISA KEV catalog, but the lack of a deterrent and the potential impact justify proactive remediation.

Generated by OpenCVE AI on October 1, 2026 at 11:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Forminator Forms to version 1.57.2.1 or later, which contains the necessary input sanitization and output escaping fixes
  • Restrict access to the Forminator Entries page so that only a minimal set of trusted administrators can view submitted entries until the plugin is updated
  • Review existing stored entries and remove or sanitize any that contain suspicious Rich‑Text content to eliminate potential residual scripts

Generated by OpenCVE AI on October 1, 2026 at 11:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions forminator Forms
Wpmudev
Wpmudev forminator Forms
Vendors & Products Wordpress-extensions
Wordpress-extensions forminator Forms
Wpmudev
Wpmudev forminator Forms

Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to open the stored submission entry in the Forminator Entries view and interact with the planted link, at which point WordPress core's jQuery-based click handler on `.contextual-help-tabs a` evaluates the entity-decoded href as HTML, firing the attacker's payload in the administrator's authenticated wp-admin session.
Title Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress-extensions Forminator Forms
Wpmudev Forminator Forms
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T18:22:36.089Z

Reserved: 2026-09-03T14:57:57.478Z

Link: CVE-2026-85235

cve-icon Vulnrichment

Updated: 2026-10-01T18:22:29.218Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T09:17:09.400

Modified: 2026-10-01T19:17:25.123

Link: CVE-2026-85235

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:36:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')