Cross-Site Scripting
18 records40.9%First: 2019. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 44 vulnerability records associated with Forminator Forms – Contact Form, Payment Form & Custom Form Builder, published between 2019 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2019 | 2 | |
| 2021 | 3 | |
| 2023 | 8 | |
| 2024 | 12 | |
| 2025 | 9 | |
| 2026 | 10 |
| Severity | Records | Share |
|---|---|---|
| Critical | 3 | 6.8% |
| High | 10 | 22.7% |
| Medium | 31 | 70.5% |
First: 2019. Latest: 2026.
First: 2023. Latest: 2026.
First: 2019. Latest: 2025.
First: 2021. Latest: 2024.
First: 2023. Latest: 2025.
First: 2023. Latest: 2024.
First: 2025. Latest: 2026.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
1.55.0.21.55.11.53.21.53.0.11.521.52.21.52.11.50.31.49.21.45.11.44.31.44.21.42.11.39.31.38.31.36.11.36.01.34.11.29.21.29.01.15.41.29.31.29.11.28.01.27.01.25.01.24.41.24.11.23.31.14.121.13.51.6Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-1.55.0.1 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.55.0.1 - Unauthenticated Stored Cross-Site Scripting | July 8, 2026 | 1.55.0.2 | High |
*-1.55.0.2 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.55.0.2 - Unauthenticated Arbitrary File Download | July 8, 2026 | 1.55.1 | High |
*-1.53.1 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.53.1 - Unauthenticated Stored Cross-Site Scripting | June 24, 2026 | 1.53.2 | High |
*-1.53.0 | Forminator Forms <= 1.53.0 - Missing Authorization to Authenticated (Subscriber+) Scheduled Form Submission Export via forminator_export_entries Action on wp_loaded Hook | May 6, 2026 | 1.53.0.1 | Medium |
*-1.51.1 | Forminator Forms <= 1.51.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'forminator_action' Parameter | May 6, 2026 | 1.52 | Medium |
*-1.52.1 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.52.1 - Unauthenticated Arbitrary File Read via 'upload-1[file][file_path]' | May 4, 2026 | 1.52.2 | High |
*-1.52.0 | Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.52.0 - Missing Authorization to Unauthenticated Stripe PaymentIntent Reuse / Underpayment Bypass via 'paymentid' Parameter | May 4, 2026 | 1.52.1 | Medium |
*-1.50.2 | Forminator <= 1.50.2 - Missing Authorization | February 22, 2026 | 1.50.3 | Medium |
*-1.50.2 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.50.2 - Authenticated (Administrator+) Stored Cross-Site Scripting | February 16, 2026 | 1.50.3 | Medium |
*-1.49.1 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.49.1 - Missing Authorization to Authenticated (Forminator User+) CSV Export | January 8, 2026 | 1.49.2 | Medium |
*-1.45.0 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.45.0 - Authenticated (Administrator+) SQL Injection via `order_by` Parameter | July 17, 2025 | 1.45.1 | Medium |
*-1.44.2 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion | July 1, 2025 | 1.44.3 | High |
*-1.44.2 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion | July 1, 2025 | 1.44.3 | High |
*-1.44.1 | Forminator <= 1.44.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via id and data-size Parameters | June 4, 2025 | 1.44.2 | Medium |
*-1.42.0 | Forminator <= 1.42.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'limit' | April 16, 2025 | 1.42.1 | Medium |
*-1.42.0 | Forminator <= 1.42.0 - Order Replay Vulnerability | April 16, 2025 | 1.42.1 | Medium |
1.39.2 | Forminator <= 1.39.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | February 26, 2025 | 1.39.3 | Medium |
*-1.38.2 | Forminator <= 1.38.2 - Reflected Cross-Site Scripting via Title Parameter | January 30, 2025 | 1.38.3 | Medium |
*-1.38.2 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.38.2 - Authenticated (Admin+) Stored Cross-Site Scripting | January 24, 2025 | 1.38.3 | Medium |
*-1.36.0 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.36.0 - Insecure Direct Object Reference to Submission Manipulation | October 30, 2024 | 1.36.1 | Medium |
*-1.35.1 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation | October 25, 2024 | 1.36.0 | High |
*-1.35.1 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Quiz Creation | October 16, 2024 | 1.36.0 | Medium |
*-1.35.1 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Custom Form Creation | October 16, 2024 | 1.36.0 | Medium |
*-1.34.0 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.34.0 - Reflected Cross-Site Scripting | September 9, 2024 | 1.34.1 | Medium |
*-1.29.1 | Forminator <= 1.29.1 - HubSpot Developer API Key Sensitive Information Exposure | August 1, 2024 | 1.29.2 | High |
Selected source records
Published: July 8, 2026
Published: July 8, 2026
Published: June 24, 2026
Published: May 6, 2026
Published: May 6, 2026
Published: May 4, 2026
Published: May 4, 2026
Published: February 22, 2026
Published: August 29, 2023
Published: April 18, 2024
Published: April 18, 2024
Published: July 1, 2025
Published: August 1, 2024
Published: July 8, 2026
Published: July 1, 2025
Published: May 4, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.