Junglewise Threat Intelligence

CVE-2026-66583: Forminator WordPress Plugin PHP Object Injection

CVE-2026-66583 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Technologies: WPMU DEV Forminator. Vendors: WPMU DEV.

Executive brief

Forminator is a popular WordPress plugin for building forms and collecting user data. An unauthenticated attacker can exploit a PHP Object Injection vulnerability to execute arbitrary code on the affected WordPress site, enabling complete server compromise and potential theft of sensitive data such as form submissions, customer information, and database credentials.

Technical details

The vulnerability is a PHP Object Injection flaw in Forminator versions 1.57.0 and earlier that does not properly validate user input before deserializing PHP objects. An unauthenticated attacker can send a malicious payload via network request to trigger deserialization of arbitrary objects, leading to remote code execution (RCE) on the affected server. No authentication is required and the vulnerability is accessible via the web interface. The vulnerability was patched in version 1.57.1.

Affected products

  • WPMU DEV Forminator 1.57.0 and earlier

Timeline

  • 2026-08-19: disclosed: Vulnerability published by Patchstack
  • 2026-08-19: patched: Patch released in version 1.57.1

References

Related threats