The Forminator Forms plugin for WordPress, which allows users to create contact forms, payment forms, and custom forms, is at risk for a type of cyber attack called Stored Cross-Site Scripting. This is due to a lack of proper security measures in the code. This vulnerability allows attackers who have Contributor-level access or higher to insert harmful code into pages that will run when a user opens the page.