Medium severity6.4NVD Advisory· Published Jun 5, 2025· Updated Jun 17, 2026
CVE-2025-5341
CVE-2025-5341
Description
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id' and 'data-size’ parameters in all versions up to, and including, 1.44.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=1.44.1
- wpmudev/Forminator Forms – Contact Form, Payment Form & Custom Form Builderv5Range: 0
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/changeset/3306475nvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/415bfddb-5223-439f-8a08-535f79631ff0nvdThird Party Advisory
- plugins.trac.wordpress.org/browser/forminator/tags/1.44.1/assets/forminator-ui/js/forminator-form.jsnvdProduct
- wordpress.org/plugins/forminator/nvdProduct
News mentions
0No linked articles in our index yet.