Stored Cross-Site Scripting Vulnerability in Forminator Forms Plugin for WordPress
CVE-2026-18325
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2026-18325?
The Forminator Forms plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability. This issue arises from inadequate input sanitization and lack of proper output escaping. An unauthenticated attacker can exploit this flaw by injecting arbitrary web scripts through forged upload records in the select field, leading to script execution on user-accessed pages. Specific functions within the plugin, such as Forminator_Core::sanitize_array(), bypass filtering for keys prefixed with 'select-', enabling attackers to create and persist malicious field records. Consequently, this vulnerability poses a significant risk to users interacting with affected forms.
Affected Version(s)
Forminator Forms β Contact Form, Payment Form & Custom Form Builder 0 <= 1.56.1