Search
Search Results (8 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-85235 | 2 Wordpress-extensions, Wpmudev | 2 Forminator Forms, Forminator Forms | 2026-10-01 | 7.2 High |
| The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to open the stored submission entry in the Forminator Entries view and interact with the planted link, at which point WordPress core's jQuery-based click handler on `.contextual-help-tabs a` evaluates the entity-decoded href as HTML, firing the attacker's payload in the administrator's authenticated wp-admin session. | ||||
| CVE-2026-92144 | 2 Wordpress-extensions, Wpmudev | 2 Forminator Forms, Forminator Forms | 2026-10-01 | 7.2 High |
| The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The required form submission nonce is freely obtainable by unauthenticated users via the publicly accessible wp_ajax_nopriv_forminator_get_nonce endpoint, making the full attack chain exploitable without any authentication or prior account. | ||||
| CVE-2026-87067 | 1 Wordpress-extensions | 1 Forminator Forms | 2026-09-28 | 8.5 High |
| The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Forminator Forms WordPress plugin before 1.57.2.1's own settings, so the issue is reachable well below administrator on sites that use that feature. | ||||
| CVE-2026-87068 | 1 Wordpress-extensions | 1 Forminator Forms | 2026-09-28 | 6.6 Medium |
| The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who submits it. The same user is refused an identical form through both the ordinary form editor and the ordinary form import. | ||||
| CVE-2026-87069 | 1 Wordpress-extensions | 1 Forminator Forms | 2026-09-28 | 3.1 Low |
| The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and that construction happens on every wp-admin request for any logged-in user. Any authenticated user, including a Subscriber with no permissions in the Forminator Forms WordPress plugin before 1.57.2.1, can therefore rewrite the saved field configuration of any form on the site, including a live payment form. | ||||
| CVE-2026-87074 | 1 Wordpress-extensions | 1 Forminator Forms | 2026-09-28 | 3.7 Low |
| The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail configuration to any address, carrying a link of their choosing inside the site's own template. The token that authorises the send is handed to the anonymous caller by the Forminator Forms WordPress plugin before 1.57.2.1 itself and can be replayed without limit. | ||||
| CVE-2026-87070 | 1 Wordpress-extensions | 1 Forminator Forms | 2026-09-28 | 5.3 Medium |
| The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwarding headers over the connecting address, and it uses that value both to enforce its per-visitor voting limit and to record who submitted an entry. Unauthenticated visitors can therefore vote without limit on any poll and can choose the address stored against every submission they make. | ||||
| CVE-2026-87071 | 1 Wordpress-extensions | 1 Forminator Forms | 2026-09-28 | 5.3 Medium |
| The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthenticated visitors submitting a public form that collects post content can attach metadata of their choosing to the post their submission creates. | ||||
Page 1 of 1.