← WordPress Vulnerabilities
WordPress security by component

Forminator

Forminator is a WordPress component with 36 published CVE records in this archive. The latest tracked vulnerability was published Jul 13, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: forminator

CVE-2026-57815: Forminator: Filesystem traversal

Forminator is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 1.55.0.2.

PublishedJul 13, 2026
Known safe version1.55.1
Safe version
Jul 13, 2026 CVE-2026-57815
Forminator: Filesystem traversal
Forminator is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 1.55.0.2.
1.55.1
CVE7.5
NVDPending
Jul 13, 2026 CVE-2026-57814
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.55.0.1.
1.55.0.2
CVE7.1
NVDPending
Jun 25, 2026 CVE-2026-56071
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.53.1.
1.53.2
CVE7.1
NVDPending
May 07, 2026 CVE-2026-6214
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: A security weakness
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.53.0.
> 1.53.0
CVE6.5
NVDPending
May 07, 2026 CVE-2026-6222
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: A security weakness
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.51.1.
> 1.51.1
CVE5.3
NVDPending
May 05, 2026 CVE-2026-2729
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: A security weakness
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.52.0.
> 1.52.0
CVE5.3
NVDPending
Mar 13, 2026 CVE-2026-32409
Forminator: A security weakness
Forminator is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jul 18, 2025 CVE-2025-7638
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: SQL injection
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.9
NVDPending
Jul 02, 2025 CVE-2025-6464
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Code execution
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVD8.8
Jul 02, 2025 CVE-2025-6463
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Code execution
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Jun 05, 2025 CVE-2025-5341
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Cross-site scripting
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Apr 17, 2025 CVE-2025-3487
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Cross-site scripting
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 17, 2025 CVE-2025-3479
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: A security weakness
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Feb 27, 2025 CVE-2025-0469
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Cross-site scripting
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 31, 2025 CVE-2025-0470
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Cross-site scripting
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 31, 2024 CVE-2024-9700
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: A security weakness
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Oct 17, 2024 CVE-2024-9352
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Cross-site request forgery
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Oct 17, 2024 CVE-2024-9351
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Cross-site request forgery
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Sep 09, 2024 CVE-2024-45625
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 02, 2024 CVE-2024-7389
Forminator: Sensitive information exposure
Forminator is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE7.5
NVDPending
Apr 23, 2024 CVE-2024-31857
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Apr 23, 2024 CVE-2024-31077
Forminator: SQL injection
Forminator is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVDPending
Apr 23, 2024 CVE-2024-28890
Forminator: Dangerous file upload
Forminator is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE5.3
NVDPending
Apr 09, 2024 CVE-2024-3053
Forminator – Contact Form, Payment Form & Custom Form Builder: Cross-site scripting
Forminator – Contact Form, Payment Form & Custom Form Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 09, 2024 CVE-2024-1794
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Mar 27, 2024 CVE-2024-29777
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Nov 20, 2023 CVE-2023-5119
Forminator: A security weakness
Forminator is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.8
NVD4.8
Nov 15, 2023 CVE-2023-6133
Forminator: Dangerous file upload
Forminator is affected by dangerous file upload. Exploitation requires an authenticated WordPress account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE6.6
NVD4.9
Aug 30, 2023 CVE-2023-4596
Forminator: Dangerous file upload
Forminator is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.8
NVDPending
Jul 31, 2023 CVE-2023-3134
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jul 12, 2023 CVE-2021-4417
Forminator – Contact Form, Payment Form & Custom Form Builder: Cross-site request forgery
Forminator – Contact Form, Payment Form & Custom Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Jul 04, 2023 CVE-2023-2010
Forminator: A security weakness
Forminator is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE3.1
NVD3.1
Mar 16, 2023 CVE-2021-36821
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Nov 23, 2021 CVE-2021-24700
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Mar 04, 2019 CVE-2019-9568
Forminator: SQL injection
Forminator is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVD6.5
Mar 04, 2019 CVE-2019-9567
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1