Unauthenticated Cross Site Scripting in Forminator Plugin by WordPress
CVE-2026-28143
7.1HIGH
What is CVE-2026-28143?
An unauthenticated Cross Site Scripting (XSS) vulnerability exists in the Forminator plugin for WordPress, impacting versions up to 1.56.0. This flaw allows attackers to inject malicious scripts into web pages that can be executed by unsuspecting users. Without proper authentication, malicious entities can exploit this vulnerability to compromise user interaction within the application, potentially leading to the disclosure of sensitive data or malicious actions on behalf of the user. It is crucial for website administrators using the affected versions to apply necessary patches and updates to mitigate the risks associated with this security flaw.
Affected Version(s)
Forminator <= 1.56.0