A vulnerability was found in WPMU DEV Forminator Forms Plugin up to 1.56.1 on WordPress. It has been rated as problematic. This affects the function Forminator_Core::sanitize_array of the component Select Field. This manipulation causes cross site scripting.

The identification of this vulnerability is CVE-2026-18325. It is possible to initiate the attack remotely. There is no exploit available.