Product
The Forminator Forms plugin for WordPress is vulnerable to Stored XSS via the 'postdata-1[post-custom]' parameter in versions 1.57.2 and below, allowing unauthenticated attackers to execute arbitrary scripts.