The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).
We have discovered 8,664 live websites that are affected by CVE-2023-5119.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 8,664 live websites (13.94% of Forminator install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 95 versions ( 74.22% of all versions) |
![]() | 2,867 websites |
![]() | 847 websites |
![]() | 757 websites |
![]() | 641 websites |
![]() | 490 websites |
![]() | 201 websites |
![]() | 196 websites |
![]() | 176 websites |
![]() | 174 websites |
![]() | 159 websites |
.com | 3,447 websites |
.dk | 680 websites |
.co.uk | 368 websites |
.org | 352 websites |
.de | 309 websites |
.fr | 287 websites |
.nl | 213 websites |
.com.au | 198 websites |
.pl | 153 websites |
.ca | 153 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | *,*** | |
********.org | ![]() | *,*** | |
*****.ru | ![]() | **,*** | |
*****.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*****************.com | ![]() | ***,*** | |
*****.org | ![]() | ***,*** | |
*******.com | ![]() | ***,*** | |
********.com | ![]() | ***,*** |
FAQ