rootpwn

high · CVSS v3 7.2

CVE-2026-85235

The Forminator Forms plugin for WordPress contains a stored XSS vulnerability in its Rich-Text Textarea Field. Unauthenticated attackers can

Overview

The Forminator Forms plugin for WordPress contains a stored XSS vulnerability in its Rich-Text Textarea Field. Unauthenticated attackers can inject scripts that execute when an administrator opens a stored entry, potentially hijacking the admin session or defacing the site. This flaw allows attackers to run arbitrary code in the context of an authenticated WordPress admin.

Description

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to open the stored submission entry in the Forminator Entries view and interact with the planted link, at which point WordPress core's jQuery-based click handler on `.contextual-help-tabs a` evaluates the entity-decoded href as HTML, firing the attacker's payload in the administrator's authenticated wp-admin session.

Impact

Confidentiality: attacker can read or steal admin session cookies. Integrity: attacker can inject malicious scripts or modify the admin interface. Availability: minimal direct impact. Impacted parties: WordPress site administrators and any users who view compromised form entries.

Remediation

1. Update Forminator Forms to the latest version (≥1.57.3) as soon as possible. 2. If an update is not immediately feasible, disable or remove the Rich-Text Textarea Field from forms, or apply custom sanitization to strip script tags. 3. Review existing stored entries for suspicious content and delete or sanitize them. 4. Ensure WordPress core and all other plugins are up to date. 5. Deploy a web application firewall or security plugin that blocks XSS payloads and monitors admin activity.

Risk context

The vulnerability is rated high severity with a CVSS v3 score of 7.2 and no EPSS data available. Attackers can exploit it without authentication, making timely patching critical to prevent potential session hijacking or defacement.

Affected products

  • WordPress
  • Forminator Forms plugin
  • Forminator Forms 1.57.2

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
—

XSS WordPress Forminator Stored XSS Admin High Severity Web Application

← All CVEs