GHSA-hqvg-xqpv-4p9r
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form fields that use pre-populated query parameters, which could lead to reflected XSS attacks.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 30, 2025 6:36 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.