CVE WATCH / VULNERABILITY DETAIL
CVE-2026-92144
HIGHCVSS 7.2NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it pos
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog