PT-2026-68374 · WordPress · Forminator Forms
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Forminator Forms – Contact Form, Payment Form & Custom Form Builder versions prior to 1.56.2
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on a target server and executed in the browser of users who visit the affected page. The issue occurs because the
sanitize array() function in Forminator Core bypasses filtering for keys starting with select-, and the set field data() function incorrectly trusts a submitted return member as an internal flag. This allows an attacker to forge and persist an upload field record containing an arbitrary file url value without validation.Recommendations
Update to a version newer than 1.56.1.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forminator Forms