CVE-2026-102388: WordPress Forminator plugin <= 1.57.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Forminator forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.57.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Forminator pluginto a version that resolves this vulnerability.Fixed in 1.58.0
Event History
Frequently Asked Questions
Which deployments are affected?
Forminator versions through 1.57.3 are affected. The available information does not identify any configuration prerequisite or unaffected configuration within that version range.
What does an attacker need to exploit this issue?
The severity vector indicates network-based exploitation with low attack complexity and no required privileges, but user interaction is required. The vulnerability is stored XSS, meaning attacker-supplied content can be retained and later executed in a user's browser.
What is the potential impact?
The provided severity vector rates confidentiality, integrity, and availability impact as low, with scope changed. Successful exploitation may affect a separate security authority or component from the vulnerable plugin.