WordPress security by component
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
Plugin description
Forminator Forms – Contact Form, Payment Form & Custom Form Builder builds contact, payment, quiz, poll, survey, and custom forms through a visual WordPress form builder.
Forminator Forms – Contact Form, Payment Form & Custom Form Builder (forminator) is a WordPress plugin with 47 published CVE records in this archive. The latest tracked vulnerability was published Aug 28, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
forminatorLatest vulnerability
CVE-2026-82220: Forminator exposes an unauthenticated state-changing operation
Forminator through 1.57.1 exposes an affected operation without authentication. An unauthenticated request can change protected plugin or site state, producing limited integrity impact.
| Safe version |
|
||
|---|---|---|---|
| Aug 28, 2026 |
CVE-2026-82220
Forminator exposes an unauthenticated state-changing operation
Forminator through 1.57.1 exposes an affected operation without authentication. An unauthenticated request can change protected plugin or site state, producing limited integrity impact.
|
1.57.2 |
CVE5.3
NVDPending
|
| Aug 28, 2026 |
CVE-2026-18324
Forminator rich-text submissions permit unauthenticated stored XSS
Forminator through 1.57.0.1 does not adequately sanitize and escape submissions to a Textarea field with the Rich-Text editor enabled. An unauthenticated submitter can store script that executes when a user views the affected submission or page.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Aug 26, 2026 |
CVE-2026-19220
Forminator permits unauthenticated multisite creation
Forminator before 1.57.1 creates multisite signups without checking whether network site registration is enabled. An unauthenticated visitor can create a new site on the WordPress multisite network and gain Administrator privileges on that site.
|
1.57.1 |
CVE3.7
NVDPending
|
| Aug 25, 2026 |
CVE-2026-18328
Forminator Stripe forms permit unauthenticated DOM-based cross-site scripting
Forminator through 1.57.0 lets an unauthenticated attacker supply script-capable error_description input that reaches a DOM rendering path without adequate sanitization or escaping. The issue is reachable on pages containing a Forminator form configured for the Stripe Checkout Sessions payment API, which became the default in 1.56.0.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Aug 25, 2026 |
CVE-2026-18323
Forminator draft submissions permit unauthenticated stored cross-site scripting
Forminator through 1.57.0.2 exposes its Save-and-Continue draft submission AJAX path to unauthenticated users. An attacker can bypass radio-field option membership validation and persist a crafted value; the bundled Inputmask library binds the stored data attribute as a callback when an administrator opens the submission in the Submissions screen, executing script in that privileged session.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Aug 20, 2026 |
CVE-2026-66583
Forminator permits unauthenticated PHP object injection
Forminator <= 1.57.0 allows an unauthenticated attacker to place attacker-controlled serialized data into an unsafe PHP deserialization path. Practical code execution depends on a usable gadget chain, but the CNA assigns high confidentiality, integrity and availability impact.
|
1.57.1 |
CVE9.8
NVDPending
|
| Aug 18, 2026 |
CVE-2026-15748
Forminator public submissions permit unauthenticated executable file upload
Forminator Forms through 1.56.1 lets an unauthenticated attacker forge a Select field value so the public submission handler trusts attacker-controlled upload-field configuration. The handle_file_upload() dangerous-extension blocklist performs exact-key matching and can be bypassed with pipe-alternative MIME type keys, allowing files that may be executable to reach the upload operation and potentially produce remote code execution.
|
> 1.56.1 |
CVE9.8
NVDPending
|
| Aug 16, 2026 |
CVE-2026-12998
Forminator Save and Continue drafts expose cross-user form data
Forminator through 1.55.0.2 does not verify ownership of the draft key supplied to forms using Save and Continue. An unauthenticated attacker can enumerate sequential integer IDs in the draft parameter and retrieve other users' saved form data, including names, email addresses, phone numbers, addresses, and free-form messages. Only forms with Save and Continue enabled are affected. The public.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 06, 2026 |
CVE-2026-28143
Forminator permits unauthenticated cross-site scripting
An unauthenticated visitor can submit attacker-controlled content that Forminator 1.56.0 and earlier renders without sufficient output encoding.
|
1.56.1 |
CVE7.1
NVDPending
|
| Aug 06, 2026 |
CVE-2026-28111
Forminator through 1.56.0 permits Contributor-level privilege escalation
A user with Contributor access can cross an authorization boundary in Forminator 1.56.0 and earlier and obtain elevated WordPress privileges. Version 1.56.0.1 is recorded as unaffected.
|
1.56.0.1 |
CVE8.8
NVDPending
|
| Aug 06, 2026 |
CVE-2026-18325
Forminator select fields permit forged upload-record stored XSS
Forminator through 1.56.1 allows an unauthenticated caller to submit crafted data through the public custom-form action, including wp_ajax_nopriv_forminator_submit_form_custom-forms. Forminator_Core::sanitize_array() skips filtering for keys beginning select-, and set_field_data() trusts a client-supplied return flag as though it came from internal plugin logic. An attacker can therefore persist a forged upload-field record containing an arbitrary nested file.file_url. Forminator_Form_Entry_Model later inserts that URL unescaped into an upload link, producing stored XSS when the affected entry is rendered. The disclosed path forges metadata; it does not establish an arbitrary file upload. The exact nested POST representation, required form configuration and victim-facing entry view are not disclosed.
|
1.56.2 |
CVE7.2
NVDPending
|
| Jul 13, 2026 |
CVE-2026-57815
Forminator: Filesystem traversal
Forminator is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 1.55.0.2.
|
1.55.1 |
CVE7.5
NVDPending
|
| Jul 13, 2026 |
CVE-2026-57814
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.55.0.1.
|
1.55.0.2 |
CVE7.1
NVDPending
|
| Jun 25, 2026 |
CVE-2026-56071
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.53.1.
|
1.53.2 |
CVE7.1
NVDPending
|
| May 07, 2026 |
CVE-2026-6214
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: A security weakness
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.53.0.
|
See mitigation notes |
CVE6.5
NVDPending
|
| May 07, 2026 |
CVE-2026-6222
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: A security weakness
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.51.1.
|
See mitigation notes |
CVE5.3
NVDPending
|
| May 05, 2026 |
CVE-2026-2729
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: A security weakness
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.52.0.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Mar 13, 2026 |
CVE-2026-32409
Forminator: A security weakness
Forminator is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jul 18, 2025 |
CVE-2025-7638
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: SQL injection
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by SQL injection. Exploitation requires an authenticated administrator account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Jul 02, 2025 |
CVE-2025-6464
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Code execution
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.5
NVD8.8
|
| Jul 02, 2025 |
CVE-2025-6463
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Code execution
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Jun 05, 2025 |
CVE-2025-5341
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Cross-site scripting
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 17, 2025 |
CVE-2025-3487
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Cross-site scripting
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 17, 2025 |
CVE-2025-3479
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: A security weakness
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Feb 27, 2025 |
CVE-2025-0469
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Cross-site scripting
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jan 31, 2025 |
CVE-2025-0470
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Cross-site scripting
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Oct 31, 2024 |
CVE-2024-9700
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Broken access control
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Oct 17, 2024 |
CVE-2024-9352
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Cross-site request forgery
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 17, 2024 |
CVE-2024-9351
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Cross-site request forgery
Forminator Forms – Contact Form, Payment Form & Custom Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 09, 2024 |
CVE-2024-45625
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 02, 2024 |
CVE-2024-7389
Forminator: Sensitive information exposure
Forminator is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Apr 23, 2024 |
CVE-2024-31857
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Apr 23, 2024 |
CVE-2024-31077
Forminator: SQL injection
Forminator is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Apr 23, 2024 |
CVE-2024-28890
Forminator: Dangerous file upload
Forminator is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Apr 09, 2024 |
CVE-2024-3053
Forminator – Contact Form, Payment Form & Custom Form Builder: Cross-site scripting
Forminator – Contact Form, Payment Form & Custom Form Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 09, 2024 |
CVE-2024-1794
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Mar 27, 2024 |
CVE-2024-29777
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Nov 20, 2023 |
CVE-2023-5119
Forminator: A security weakness
Forminator is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Nov 15, 2023 |
CVE-2023-6133
Forminator: Dangerous file upload
Forminator is affected by dangerous file upload. Exploitation requires an authenticated administrator account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE6.6
NVD4.9
|
| Aug 30, 2023 |
CVE-2023-4596
Forminator: Dangerous file upload
Forminator is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Jul 31, 2023 |
CVE-2023-3134
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jul 12, 2023 |
CVE-2021-4417
Forminator – Contact Form, Payment Form & Custom Form Builder: Cross-site request forgery
Forminator – Contact Form, Payment Form & Custom Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD4.3
|
| Jul 04, 2023 |
CVE-2023-2010
Forminator: A security weakness
Forminator is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD3.1
|
| Mar 16, 2023 |
CVE-2021-36821
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Nov 23, 2021 |
CVE-2021-24700
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Mar 04, 2019 |
CVE-2019-9568
Forminator: SQL injection
Forminator is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Mar 04, 2019 |
CVE-2019-9567
Forminator: Cross-site scripting
Forminator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|