What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator.This issue affects Forminator: from n/a through <= 1.29.0.
Explanation of Vulnerability in Simple Terms
02Summary
Forminator versions up to 1.29.0 contain a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into form pages. An attacker can craft a malicious link that, when visited by a site user, executes JavaScript in their browser with access to the site's data and functionality. The vulnerability affects the form rendering logic and can impact both site visitors and administrators.
What an attacker can do
03Attacker Capabilities
Inject and execute malicious JavaScript in a user's browser when they visit a crafted link to a form page.
Potential impact on your site
04Site Impact
Site visitors and admins can be tricked into running attacker code, risking credential theft, session hijacking, or malware distribution.
Conditions required to exploit
05Prerequisites
The victim must click a malicious link or visit a page containing the exploit. No authentication required.
Key dates
06Disclosure timeline
March 27, 2024
CVE published
May 11, 2026
Record updated