Stored Cross-Site Scripting in Forminator Forms WordPress Plugin
The Forminator Forms plugin for WordPress is vulnerable to Stored XSS via the 'postdata-1[post-custom]' parameter in versions 1.57.2 and below, allowing unauthenticated attackers to execute arbitrary scripts.
CVE search metadata
CVE search record: CVE-2026-92144. Severity: high. CVSS: 7.2. KEV: no. Product: Forminator Forms (<= 1.57.2). Brief: Stored Cross-Site Scripting in Forminator Forms WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-forminator-xss/
The Forminator Forms - Contact Form, Payment Form & Custom Form Builder plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-92144. All versions up to and including 1.57.2 are impacted due to insufficient input sanitization and output escaping on the 'postdata-1[post-custom]' parameter. The vulnerability allows unauthenticated attackers to inject arbitrary web scripts into form submissions, which are subsequently stored and executed when a user or administrator views the page containing the injected content. The attack is highly accessible because the form submission nonce, typically a security barrier, is exposed to unauthenticated users via the publicly accessible 'wp_ajax_nopriv_forminator_get_nonce' endpoint. Successful exploitation results in the execution of unauthorized JavaScript in the context of the victim's session, potentially leading to session hijacking, defacement, or administrative action performance.
Impact
The vulnerability poses a significant risk to WordPress sites utilizing the Forminator plugin. Successful exploitation allows unauthenticated attackers to execute malicious scripts in the browsers of users or administrators viewing the site. This could lead to account takeover, unauthorized data access, or the redirection of site traffic to malicious domains. Given the plugin's broad utility in contact and payment forms, high-traffic sites may be particularly attractive targets.
Recommendation
Prioritized actions for security teams:
- Update the Forminator Forms plugin to a version released after 1.57.2 immediately upon availability of a patch.
- Monitor web server logs for requests to 'wp_ajax_nopriv_forminator_get_nonce' followed by POST requests to the plugin's submission endpoints containing script tags or abnormal characters in the 'postdata-1[post-custom]' parameter.
- Deploy WAF rules to sanitize or block POST requests containing HTML tags or script-related keywords ('<script>', 'onload=', 'onerror=') directed toward Forminator submission endpoints.
Immediate actions
Review logs for requests containing script tags toward form submission endpoints
Mitigations
Upgrade Forminator Forms to the first patched version released after 1.57.2
CVE-2026-92144
Detection coverage 1
Detect CVE-2026-92144 Exploitation - Stored XSS in Forminator Forms
highDetects exploitation attempts targeting CVE-2026-92144 where a user submits a POST request to Forminator endpoints containing HTML script tags or event handlers.
Detection queries are available on the platform. Get full rules →