Description
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The required form submission nonce is freely obtainable by unauthenticated users via the publicly accessible wp_ajax_nopriv_forminator_get_nonce endpoint, making the full attack chain exploitable without any authentication or prior account.
Published: 2026-10-01
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Unauthenticated Stored Cross‑Site Scripting
Action: Patch Immediately
AI Analysis

Impact

The vulnerability allows an attacker to store malicious JavaScript within the "postdata-1[post-custom]" parameter of the Forminator Forms plugin. Because the input is not properly sanitized and the output is not escaped, the injected script is persisted in the database and executed whenever a user views the affected page. This leads to the execution of arbitrary code in the victim’s browser, enabling session hijacking, defacement, or the delivery of further malware. The weakness is a classic Stored XSS identified as CWE‑79.

Affected Systems

WordPress installations running the Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin at version 1.57.2 or earlier are affected. The vulnerability exists across all earlier releases of the plugin and applies to all sites that have the plugin activated.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity for XSS that does not require authentication. The attack chain relies on an unauthenticated request to obtain a form submission nonce from the publicly accessible wp_ajax_nopriv_forminator_get_nonce endpoint, making the exploit straightforward for anyone with internet access to the site. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, but given the lack of authentication requirements and the persistence of the XSS payload, the practical risk remains significant.

Generated by OpenCVE AI on October 1, 2026 at 10:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Forminator Forms plugin to version 1.57.3 or newer, which removes the vulnerable parameter handling.
  • If an update is not immediately possible, remove or deactivate the Forminator Forms plugin to eliminate the attack surface.
  • As a temporary mitigation, configure the site’s web‑application firewall or content‑security‑policy to block inline script execution and redundant script tags, reducing the impact of any stored payloads that may already exist.

Generated by OpenCVE AI on October 1, 2026 at 10:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Description The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The required form submission nonce is freely obtainable by unauthenticated users via the publicly accessible wp_ajax_nopriv_forminator_get_nonce endpoint, making the full attack chain exploitable without any authentication or prior account.
Title Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T14:14:09.835Z

Reserved: 2026-09-15T17:08:52.563Z

Link: CVE-2026-92144

cve-icon Vulnrichment

Updated: 2026-10-01T14:14:07.267Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T10:17:17.370

Modified: 2026-10-01T15:17:35.403

Link: CVE-2026-92144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T10:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')