Executive brief
Forminator is a popular WordPress plugin for building forms and collecting user data. An unauthenticated attacker can exploit a PHP Object Injection vulnerability to execute arbitrary code on the affected WordPress site, enabling complete server compromise and potential theft of sensitive data such as form submissions, customer information, and database credentials.
Technical details
The vulnerability is a PHP Object Injection flaw in Forminator versions 1.57.0 and earlier that does not properly validate user input before deserializing PHP objects. An unauthenticated attacker can send a malicious payload via network request to trigger deserialization of arbitrary objects, leading to remote code execution (RCE) on the affected server. No authentication is required and the vulnerability is accessible via the web interface. The vulnerability was patched in version 1.57.1.
Affected products
- WPMU DEV Forminator 1.57.0 and earlier
Timeline
- 2026-08-19: disclosed: Vulnerability published by Patchstack
- 2026-08-19: patched: Patch released in version 1.57.1