Impact
The vulnerability allows an attacker to store malicious JavaScript within the "postdata-1[post-custom]" parameter of the Forminator Forms plugin. Because the input is not properly sanitized and the output is not escaped, the injected script is persisted in the database and executed whenever a user views the affected page. This leads to the execution of arbitrary code in the victim’s browser, enabling session hijacking, defacement, or the delivery of further malware. The weakness is a classic Stored XSS identified as CWE‑79.
Affected Systems
WordPress installations running the Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin at version 1.57.2 or earlier are affected. The vulnerability exists across all earlier releases of the plugin and applies to all sites that have the plugin activated.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity for XSS that does not require authentication. The attack chain relies on an unauthenticated request to obtain a form submission nonce from the publicly accessible wp_ajax_nopriv_forminator_get_nonce endpoint, making the exploit straightforward for anyone with internet access to the site. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, but given the lack of authentication requirements and the persistence of the XSS payload, the practical risk remains significant.
OpenCVE Enrichment