PT-2026-81190 · WordPress · Forminator

·

CVE-2026-18328

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Forminator Forms – Contact Form, Payment Form & Custom Form Builder versions prior to 1.58.0
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform DOM-Based Reflected Cross-Site Scripting. This occurs when arbitrary web scripts are injected into pages, which then execute upon user access. The issue is specifically triggerable on pages hosting a form configured to use the Stripe Checkout Sessions payment API via the error description parameter.
Recommendations Update to a version newer than 1.57.0. Avoid using the error description parameter in the Stripe Checkout Sessions payment API configuration until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18328

Affected Products

Forminator