CVE-2023-5119

Forminator and Forminator Pro < 1.27.0 - Admin+ Stored Cross-Site Scripting

The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).


We have discovered 8,664 live websites that are affected by CVE-2023-5119.

Test my site




Affected Software

Product  Forminator
Category Wordpress Plugins
Vulnerable Domains8,664 live websites (13.94% of Forminator install base)
Vulnerable Versions
  • from 0 before 1.27
Vulnerable Versions Count95 versions ( 74.22% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Nov 20, 2023
  • Updated - Aug 2, 2024

Credits

  • Mohamed Azarudheen (finder)
  • WPScan (coordinator)

CVE-2023-5119 usage by Country

United States2,867 websites



Germany847 websites
Denmark757 websites
France641 websites
GB490 websites
Netherlands201 websites
Poland196 websites
South Africa176 websites
Cyprus174 websites
Italy159 websites

CVE-2023-5119 usage by TLD

.com3,447 websites
.dk680 websites
.co.uk368 websites
.org352 websites
.de309 websites
.fr287 websites
.nl213 websites
.com.au198 websites
.pl153 websites
.ca153 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-5119

Top websites that are affected by CVE-2023-5119. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
********.org United States*,***
*****.ru Russia**,***
*****.com United States**,***
************.com United States**,***
***********.com United States**,***
*****************.com United States***,***
*****.org United States***,***
*******.com United States***,***
********.com United States***,***
See full domain list

FAQ

CVE-2023-5119 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Forminator
A total of 8,664 websites have been identified as vulnerable to CVE-2023-5119, discovered through global website indexing conducted by WebTechSurvey.
Forminator is susceptible to CVE-2023-5119 vulnerability.
Forminator versions before 1.27 are vulnerable to CVE-2023-5119.
Version 1.27 of Forminator addresses the CVE-2023-5119 security vulnerability.