Sceawere
Vulnerability Detail
CVE-2026-102388UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Forminator Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- WPMU DEV
- Product
- Forminator
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Forminator forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.57.3.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-10T14:16:36.167Z",
"pubdate": "2026-10-10T14:16:36.167Z",
"executiveSummary": "The WPMU DEV Forminator plugin for WordPress contains an Improper Neutralization of Input During Web Page Generation vulnerability, classified as Stored Cross-Site Scripting (XSS).\nThis flaw allows authenticated or unauthenticated attackers to inject malicious JavaScript into web pages generated by the Forminator plugin, which is then stored within the application database.\nWhen a victim, such as an administrator or a user with elevated privileges, views the affected form entries or submission logs, the malicious script executes within the context of the user's browser session.\nSuccessful exploitation can result in unauthorized actions performed on behalf of the victim, session hijacking, credential theft, or unauthorized redirection.\nThe vulnerability affects all versions of Forminator from n/a through 1.57.3.\nThe primary risk lies in the compromise of administrative sessions and the potential for persistent malicious code execution within the WordPress dashboard environment.",
"technicalDetails": "The vulnerability exists due to insufficient sanitization and validation of user-supplied input submitted through Forminator forms before that data is rendered back to the browser within the administrative interface.\nWhen a user submits data via a Forminator form, the input is saved to the WordPress database. If the plugin fails to properly encode or escape this data during the retrieval and rendering process in the WordPress backend, injected scripts are interpreted as legitimate HTML/JavaScript by the browser.\nThe root cause is a failure to implement robust output encoding (e.g., using WordPress functions like esc_html() or esc_js()) when displaying user-submitted form data within the dashboard.\nAttack flow: First, an attacker identifies a publicly accessible Forminator form. Second, the attacker submits a specially crafted payload—such as a <script> tag or an HTML element with an 'onmouseover' event handler—into a form field designed to accept text input. Third, the plugin stores this payload in the database. Fourth, a privileged user, such as an administrator, accesses the 'Forminator' submission management area to review entries. Finally, when the dashboard renders the list of submissions, the browser executes the stored payload.\nBecause the payload resides within the database, the execution is persistent; every time the victim views the malicious entry, the script triggers.\nIn a post-exploitation scenario, the attacker can leverage the victim's session to perform administrative tasks, such as creating new rogue accounts, modifying plugin settings, or injecting further malicious payloads into other areas of the WordPress installation.\nSince the attack executes within the context of the WordPress admin panel, the malicious script benefits from the victim's authentication state, effectively bypassing standard perimeter defenses.\nThis vulnerability requires no specific interaction from the victim other than the act of viewing the submitted data, making it a classic Stored XSS vector that exploits the trust relationship between the administrative interface and stored user input."
}