Executive brief
Forminator is a WordPress plugin that lets users create contact forms, payment forms, and custom forms. The plugin fails to validate user input before processing shortcodes in front-end actions, allowing attackers without login credentials to execute arbitrary shortcodes. This can lead to data exposure, injection of malicious content, or site compromise depending on what shortcodes are available and what they can do.
Technical details
The vulnerability exists in the front-end action processing logic (abstract-class-front-action.php and front-action.php) where user-supplied values are passed directly to do_shortcode() without proper sanitization or validation. An unauthenticated attacker can inject malicious shortcode syntax via form submissions or requests to execute arbitrary shortcodes, potentially escalating to remote code execution if dangerous shortcodes are enabled on the WordPress site.
Affected products
- WPForms Forminator up to 1.57.2
Timeline
- 2026-09-19: disclosed: CVE-2026-92229 published