← Back
Web Application
CVE-2026-18325 high CVSS 7.2

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...

Summary

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...

AI summary openai / gpt-4o

WordPressプラグイン「Forminator Forms」のバージョン1.56.1以下において、保存型クロスサイトスクリプティングの脆弱性が見つかりました。この脆弱性は、フィールドの入力値が適切にエスケープ・サニタイズされないため、未認証の攻撃者により悪意のあるスクリプトがページに注入される可能性を生じさせます。
❓ What is the problem
WordPressプラグイン「Forminator Forms」における保存型クロスサイトスクリプティングの脆弱性。
📍 Affected scope
プラグインのバージョン1.56.1以下。
🔥 Severity
未認証の攻撃者がスクリプトを注入し、ユーザーがページをアクセスした際に実行され得るため、重大な脆弱性である。
🔧 How to fix
プラグインを更新し、入力値のサニタイズとエスケープを強化することで修正可能。
🛡️ Workaround
特になし
🔍 Detection
プラグインのバージョンを確認し、脆弱なバージョンがインストールされているか確認する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →