{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-92144/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpmu_dev:forminator_forms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-92144"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Forminator Forms (\u003c= 1.57.2)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","stored-xss","wordpress","cve-2026-92144"],"_cs_type":"advisory","_cs_vendors":["WPMU DEV"],"content_html":"\u003cp\u003eThe Forminator Forms - Contact Form, Payment Form \u0026amp; Custom Form Builder plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-92144. All versions up to and including 1.57.2 are impacted due to insufficient input sanitization and output escaping on the 'postdata-1[post-custom]' parameter. The vulnerability allows unauthenticated attackers to inject arbitrary web scripts into form submissions, which are subsequently stored and executed when a user or administrator views the page containing the injected content. The attack is highly accessible because the form submission nonce, typically a security barrier, is exposed to unauthenticated users via the publicly accessible 'wp_ajax_nopriv_forminator_get_nonce' endpoint. Successful exploitation results in the execution of unauthorized JavaScript in the context of the victim's session, potentially leading to session hijacking, defacement, or administrative action performance.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to WordPress sites utilizing the Forminator plugin. Successful exploitation allows unauthenticated attackers to execute malicious scripts in the browsers of users or administrators viewing the site. This could lead to account takeover, unauthorized data access, or the redirection of site traffic to malicious domains. Given the plugin's broad utility in contact and payment forms, high-traffic sites may be particularly attractive targets.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Forminator Forms plugin to a version released after 1.57.2 immediately upon availability of a patch.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for requests to 'wp_ajax_nopriv_forminator_get_nonce' followed by POST requests to the plugin's submission endpoints containing script tags or abnormal characters in the 'postdata-1[post-custom]' parameter.\u003c/li\u003e\n\u003cli\u003eDeploy WAF rules to sanitize or block POST requests containing HTML tags or script-related keywords ('\u0026lt;script\u0026gt;', 'onload=', 'onerror=') directed toward Forminator submission endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T10:40:46Z","date_published":"2026-10-01T10:40:46Z","id":"https://feed.craftedsignal.io/briefs/2026-10-forminator-xss/","summary":"The Forminator Forms plugin for WordPress is vulnerable to Stored XSS via the 'postdata-1[post-custom]' parameter in versions 1.57.2 and below, allowing unauthenticated attackers to execute arbitrary scripts.","title":"Stored Cross-Site Scripting in Forminator Forms WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-forminator-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-92144","version":"https://jsonfeed.org/version/1.1"}