5.3
CVE-2026-12998
- EPSS 0.3%
- Veröffentlicht 16.08.2026 06:38:07
- Zuletzt bearbeitet 20.08.2026 12:48:10
- CVE-Watchlists
- Unerledigt
Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter
Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the 'draft' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate sequential integer entry IDs via the 'draft' parameter and read other users' saved draft form data, including names, email addresses, phone numbers, addresses, and free-form message content. This is only exploitable on forms that have the 'Save and Continue' feature enabled.
Mögliche Gegenmaßnahme
Forminator Forms – Contact Form, Payment Form & Custom Form Builder: Update to version 1.55.1, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerwpmudev
≫
Produkt
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
Default Statusunaffected
Version <=
1.55.0.2
Version
0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
Version
*-1.55.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.228 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://www.wordfence.com/threat-intel/vulnerabilities/id/36aa7193-0e31-4084-97d0-8c22ebff3f05?source=cve
https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.0/library/render/class-render-form.php#L2011
https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.0/library/render/class-render-form.php#L2000
https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.0/library/model/class-form-entry-model.php#L160
https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.0/library/model/class-form-entry-model.php#L212
https://plugins.trac.wordpress.org/browser/forminator/tags/1.52.2/library/render/class-render-form.php#L2011
https://plugins.trac.wordpress.org/browser/forminator/tags/1.52.2/library/render/class-render-form.php#L2000
https://plugins.trac.wordpress.org/browser/forminator/tags/1.52.2/library/model/class-form-entry-model.php#L160
https://plugins.trac.wordpress.org/browser/forminator/tags/1.52.2/library/model/class-form-entry-model.php#L212
https://plugins.trac.wordpress.org/changeset?reponame=&old=3593819%40forminator&new=3593819%40forminator
https://www.wordfence.com/threat-intel/vulnerabilities/id/36aa7193-0e31-4084-97d0-8c22ebff3f05