CVE-2025-5341: Forminator <= 1.44.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via id and data-size Parameters
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id' and 'data-size’ parameters in all versions up to, and including, 1.44.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5341?
CVE-2025-5341 is classified as a medium severity vulnerability due to its potential for Stored Cross-Site Scripting.
How do I fix CVE-2025-5341?
To fix CVE-2025-5341, update the Forminator Forms plugin to the latest version beyond 1.44.1.
What impacts does CVE-2025-5341 have on website security?
CVE-2025-5341 can allow attackers to inject malicious scripts into user sessions, compromising user data and site integrity.
Who is affected by CVE-2025-5341?
All users of the Forminator Forms plugin for WordPress versions up to and including 1.44.1 are affected by CVE-2025-5341.
What causes CVE-2025-5341?
CVE-2025-5341 is caused by insufficient input sanitization and output escaping in the plugin's handling of 'id' and 'data-size' parameters.