Stored XSS Vulnerability in WPMU DEV Forminator Plugin
CVE-2026-102388
7.1HIGH
What is CVE-2026-102388?
A vulnerability in the WPMU DEV Forminator plugin allows attackers to exploit improper input neutralization during web page generation, leading to stored cross-site scripting (XSS) attacks. This vulnerability affects versions from n/a through 1.57.3, allowing malicious scripts to be stored and executed on victim's browsers when they visit affected pages.
Affected Version(s)
Forminator 0 <= 1.57.3