PT-2026-68374 · WordPress · Forminator Forms

·

CVE-2026-18325

·

Published

2026-08-06

·

Updated

2026-08-06

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Forminator Forms – Contact Form, Payment Form & Custom Form Builder versions prior to 1.56.2
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on a target server and executed in the browser of users who visit the affected page. The issue occurs because the sanitize array() function in Forminator Core bypasses filtering for keys starting with select-, and the set field data() function incorrectly trusts a submitted return member as an internal flag. This allows an attacker to forge and persist an upload field record containing an arbitrary file url value without validation.
Recommendations Update to a version newer than 1.56.1.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18325

Affected Products

Forminator Forms