Stored Cross-Site Scripting Vulnerability in Forminator Forms Plugin for WordPress
CVE-2026-2002
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 February 2026
What is CVE-2026-2002?
The Forminator Forms plugin for WordPress is exposed to a Stored Cross-Site Scripting vulnerability through the form_name parameter across all versions up to and including 1.50.2. Due to inadequate input sanitization and output escaping, this vulnerability allows authenticated users with administrator-level access to execute malicious web scripts on pages accessed by other users. The plugin's feature of enabling form management permissions for lower-level users increases the risk of exploitation, potentially impacting subscribers and other non-admin roles.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Forminator Forms – Contact Form, Payment Form & Custom Form Builder * <= 1.50.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved