What is CVE-2026-18325?
The Forminator Forms plugin for WordPress (versions up to and including 1.56.1) contains a Stored Cross-Site Scripting (XSS) vulnerability via forged upload records through the Select Field due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to execute arbitrary scripts in a user's browser. Immediate update to the latest version is strongly recommended.
Azərbaycanca: WordPress üçün Forminator Forms plaginində (1.56.1 və əvvəlki versiyalar) Select Field vasitəsilə saxta yükləmə qeydləri ilə Stored Cross-Site Scripting (XSS) zəifliyi aşkarlanıb. Bu, yetərsiz input sanitization və output escaping səbəbindən autentifikasiya olunmamış hücumçulara istifadəçi brauzerində ixtiyari skript icra etməyə imkan verir. Plagini dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What does the CVE-2026-18325 vulnerability in the Forminator Forms plugin allow?
This vulnerability allows unauthenticated attackers to perform a Stored XSS attack via forged upload records through the Select Field.
Which versions of Forminator Forms are affected by CVE-2026-18325?
This vulnerability affects Forminator Forms plugin versions up to and including 1.56.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.