Cross-Site Scripting
18 records40.9%First: 2019. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 44 vulnerability records associated with Forminator Forms – Contact Form, Payment Form & Custom Form Builder, published between 2019 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2019 | 2 | |
| 2021 | 3 | |
| 2023 | 8 | |
| 2024 | 12 | |
| 2025 | 9 | |
| 2026 | 10 |
| Severity | Records | Share |
|---|---|---|
| Critical | 3 | 6.8% |
| High | 10 | 22.7% |
| Medium | 31 | 70.5% |
First: 2019. Latest: 2026.
First: 2023. Latest: 2026.
First: 2019. Latest: 2025.
First: 2021. Latest: 2024.
First: 2023. Latest: 2025.
First: 2023. Latest: 2024.
First: 2025. Latest: 2026.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
1.55.0.21.55.11.53.21.53.0.11.521.52.21.52.11.50.31.49.21.45.11.44.31.44.21.42.11.39.31.38.31.36.11.36.01.34.11.29.21.29.01.15.41.29.31.29.11.28.01.27.01.25.01.24.41.24.11.23.31.14.121.13.51.6Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-1.28.1 | Forminator <= 1.28.1 - Unauthenticated Arbitrary File Upload | April 18, 2024 | 1.29.0 | Critical |
*-1.15.2 | Forminator <= 1.15.2 - Reflected Cross-Site Scripting | April 18, 2024 | 1.15.4 | Medium |
*-1.29.2 | Forminator <= 1.29.2 - Authenticated (Admin+) SQL Injection | April 18, 2024 | 1.29.3 | Critical |
*-1.29.2 | Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.29.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via forminator_form Shortcode | April 8, 2024 | 1.29.3 | Medium |
*-1.29.0 | Forminator <= 1.29.0 - Unauthenticated Stored Cross-Site Scripting via File Upload | March 29, 2024 | 1.29.1 | High |
*-1.29.0 | Forminator <= 1.29.0 - Reflected Cross-Site Scripting | March 25, 2024 | 1.29.1 | Medium |
*-1.27.0 | Forminator <= 1.27.0 - Authenticated (Administrator+) Arbitrary File Upload | November 14, 2023 | 1.28.0 | Medium |
*-1.26.0 | Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.27.0 - Authenticated (Admin+) Stored Cross-Site Scripting | October 27, 2023 | 1.27.0 | Medium |
*-1.24.6 | Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload | August 29, 2023 | 1.25.0 | Critical |
*-1.24.1 | Forminator <= 1.24.1 - Reflected Cross-Site Scripting | July 10, 2023 | 1.24.4 | Medium |
*-1.23.3 | Forminator <= 1.23.3 - Race Condition to Multiple Poll Voting | June 12, 2023 | 1.24.1 | Medium |
*-1.22.1 | Forminator <= 1.22.1 - Missing Authorization on 'hubspot_support_request' AJAX function | April 12, 2023 | 1.23.3 | Medium |
*-1.22.1 | Forminator <= 1.22.1 - Missing Authorization on 'load_recaptcha_preview' AJAX function | April 12, 2023 | 1.23.3 | Medium |
*-1.22.1 | Forminator <= 1.22.1 - Missing Authorization on 'load_hcaptcha_preview' AJAX function | April 12, 2023 | 1.23.3 | Medium |
[*, 1.15.4) | Forminator <= 1.15.2 - Admin+ Stored Cross-Site Scripting | October 20, 2021 | 1.15.4 | Medium |
[*, 1.14.12) | Forminator <= 1.14.11 - Unauthenticated Stored Cross-Site Scripting | July 14, 2021 | 1.14.12 | High |
[*, 1.13.5) | Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.13.4 - Cross-Site Request Forgery Bypass | March 1, 2021 | 1.13.5 | Medium |
[*, 1.6) | Forminator Plugin <= 1.5.3.1 - SQL Injection | February 6, 2019 | 1.6 | Medium |
[*, 1.6) | Forminator Plugin <= 1.5.4 - Cross-Site Scripting | February 6, 2019 | 1.6 | Medium |
Selected source records
Published: July 8, 2026
Published: July 8, 2026
Published: June 24, 2026
Published: May 6, 2026
Published: May 6, 2026
Published: May 4, 2026
Published: May 4, 2026
Published: February 22, 2026
Published: August 29, 2023
Published: April 18, 2024
Published: April 18, 2024
Published: July 1, 2025
Published: August 1, 2024
Published: July 8, 2026
Published: July 1, 2025
Published: May 4, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.