{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/forminator-forms--contact-form-payment-form--custom-form-builder--1.57.0.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-18324"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Forminator Forms – Contact Form, Payment Form \u0026 Custom Form Builder (\u003c= 1.57.0.1)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["WPMU DEV"],"content_html":"\u003cp\u003eThe Forminator Forms - Contact Form, Payment Form \u0026amp; Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) through its Rich-Text Textarea field component. This vulnerability, tracked as CVE-2026-18324, affects all plugin versions up to and including 1.57.0.1. The flaw stems from insufficient input sanitization and output escaping when processing content submitted through the Rich-Text editor.\u003c/p\u003e\n\u003cp\u003eBecause the vulnerability is unauthenticated, an external actor can craft a payload containing arbitrary JavaScript and submit it via a public-facing form that utilizes a Rich-Text Textarea field. The payload is stored on the server and executes in the browser of any user (such as an administrator or other site visitor) who views the page containing the rendered input. This poses a significant risk for session hijacking, unauthorized actions performed on behalf of legitimate users, and potential defacement of the WordPress site. Organizations using this plugin should verify if the Rich-Text editor is enabled on any publicly accessible forms and restrict access or patch immediately to version 1.57.0.2 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated attackers to execute arbitrary JavaScript within the context of a victim's session. In WordPress environments, this typically leads to the theft of administrative session cookies, unauthorized modification of site content, creation of new administrative accounts, or redirection of users to malicious infrastructure. The exploitability is limited to forms where the specific Rich-Text editor component is actively configured.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Forminator Forms plugin to version 1.57.0.2 or later immediately to patch CVE-2026-18324.\u003c/li\u003e\n\u003cli\u003eAudit existing WordPress forms to identify and disable the Rich-Text editor option on public-facing Textarea fields until patching is complete.\u003c/li\u003e\n\u003cli\u003eMonitor web application firewall (WAF) logs for POST requests containing script tags or event handlers directed at endpoints used by the Forminator plugin.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T07:11:40Z","date_published":"2026-08-28T07:11:40Z","id":"https://feed.craftedsignal.io/briefs/2026-08-forminator-xss/","summary":"The Forminator Forms WordPress plugin (up to v1.57.0.1) is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via the Rich-Text Textarea field, allowing malicious script execution in the context of victim browsers.","title":"Stored XSS Vulnerability in Forminator Forms WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-forminator-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Forminator Forms – Contact Form, Payment Form \u0026 Custom Form Builder (\u003c= 1.57.0.1)","version":"https://jsonfeed.org/version/1.1"}