<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Forminator Forms – Contact Form, Payment Form &amp; Custom Form Builder (&lt;= 1.57.0.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/forminator-forms--contact-form-payment-form--custom-form-builder--1.57.0.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 28 Aug 2026 07:11:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/forminator-forms--contact-form-payment-form--custom-form-builder--1.57.0.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS Vulnerability in Forminator Forms WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-08-forminator-xss/</link><pubDate>Fri, 28 Aug 2026 07:11:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-forminator-xss/</guid><description>The Forminator Forms WordPress plugin (up to v1.57.0.1) is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via the Rich-Text Textarea field, allowing malicious script execution in the context of victim browsers.</description><content:encoded><![CDATA[<p>The Forminator Forms - Contact Form, Payment Form &amp; Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) through its Rich-Text Textarea field component. This vulnerability, tracked as CVE-2026-18324, affects all plugin versions up to and including 1.57.0.1. The flaw stems from insufficient input sanitization and output escaping when processing content submitted through the Rich-Text editor.</p>
<p>Because the vulnerability is unauthenticated, an external actor can craft a payload containing arbitrary JavaScript and submit it via a public-facing form that utilizes a Rich-Text Textarea field. The payload is stored on the server and executes in the browser of any user (such as an administrator or other site visitor) who views the page containing the rendered input. This poses a significant risk for session hijacking, unauthorized actions performed on behalf of legitimate users, and potential defacement of the WordPress site. Organizations using this plugin should verify if the Rich-Text editor is enabled on any publicly accessible forms and restrict access or patch immediately to version 1.57.0.2 or later.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows unauthenticated attackers to execute arbitrary JavaScript within the context of a victim's session. In WordPress environments, this typically leads to the theft of administrative session cookies, unauthorized modification of site content, creation of new administrative accounts, or redirection of users to malicious infrastructure. The exploitability is limited to forms where the specific Rich-Text editor component is actively configured.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Forminator Forms plugin to version 1.57.0.2 or later immediately to patch CVE-2026-18324.</li>
<li>Audit existing WordPress forms to identify and disable the Rich-Text editor option on public-facing Textarea fields until patching is complete.</li>
<li>Monitor web application firewall (WAF) logs for POST requests containing script tags or event handlers directed at endpoints used by the Forminator plugin.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>xss</category><category>wordpress</category></item></channel></rss>