PT-2026-81190 · WordPress · Forminator
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Forminator Forms – Contact Form, Payment Form & Custom Form Builder versions prior to 1.58.0
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform DOM-Based Reflected Cross-Site Scripting. This occurs when arbitrary web scripts are injected into pages, which then execute upon user access. The issue is specifically triggerable on pages hosting a form configured to use the Stripe Checkout Sessions payment API via the
error description parameter.Recommendations
Update to a version newer than 1.57.0.
Avoid using the
error description parameter in the Stripe Checkout Sessions payment API configuration until the update is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forminator