Executive brief
Forminator is a WordPress plugin used to create and manage contact forms and lead capture forms on websites. An unauthenticated vulnerability in versions 1.57.1 and earlier allows attackers to exploit the plugin without authentication, potentially exposing sensitive form data or enabling unauthorized form manipulation.
Technical details
The vulnerability is classified as an "Other Vulnerability Type" under OWASP A4 (Insecure Design) with no specific technical root cause disclosed in available sources. It affects Forminator plugin versions up to and including 1.57.1 and can be exploited without authentication (network attack vector). The exact attack mechanism and achievable impact are not detailed in the advisory, but the CVSS 5.3 score suggests moderate risk. A patch is available in version 1.57.2.
Affected products
- WPMU DEV Forminator <=1.57.1
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Fix available in version 1.57.2