CVE-2026-2002
The Forminator Forms β Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form_name parameter in all versions up to, and including, 1.50.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin allows admins to give form management permissions to lower level users, which could make this exploitable by users such as subscribers.
- Affected products
- Forminator Forms
- CVSS 3.1
- 4.4 MEDIUM
- EPSS
- 0.2% (6th percentile)
- Weakness
- CWE-79
- NVD status
- Deferred
- Published
- 2026-02-17
CVE-2026-2002 at NVD
2 known exploits for CVE-2026-2002
Proof-of-concept code and exploit modules indexed by Sploitus