The Forminator plugin for WordPress is unsafe in versions up to 1.24.1 because of a lack of proper input sanitization and output escaping. This means unauthenticated attackers can inject malicious web scripts into pages that would run if a user clicks on a link they were tricked into clicking.