Stored Cross-Site Scripting Vulnerability in Forminator Forms by WPMU DEV
CVE-2026-18323
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-18323?
The Forminator Forms plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability through its Radio Field feature (Save and Continue Draft) in all versions up to and including 1.57.0.2. This vulnerability arises from insufficient input sanitization and output escaping, enabling attackers to inject arbitrary scripts into user-accessible pages. The pipeline for exploitation is facilitated by the nopriv registration of the AJAX endpoint for draft submissions, which allows unauthenticated attackers to bypass validations and persist malicious payloads. These payloads can be executed automatically on the Submissions admin page via the Inputmask library's data-attribute callback binding, potentially compromising the security of the affected WordPress sites.
Affected Version(s)
Forminator Forms β Contact Form, Payment Form & Custom Form Builder 0 <= 1.57.0.2