CVE-2026-6214
- EPSS 0.44%
- Veröffentlicht 07.05.2026 04:16:35
- Zuletzt bearbeitet 07.05.2026 14:00:05
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_for_saving_export_schedule() function in library/class-export.php failing to perform a capability check...
CVE-2026-6222
- EPSS 0.43%
- Veröffentlicht 07.05.2026 01:25:27
- Zuletzt bearbeitet 07.05.2026 14:00:05
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method in `Forminator_Admin_Module_Edit_Page` (admin/abstracts/class-admin-module-edit-page...
CVE-2026-2729
- EPSS 0.37%
- Veröffentlicht 05.05.2026 07:15:59
- Zuletzt bearbeitet 05.05.2026 19:08:20
The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. This is due to the plugin not properly verifying that a user is authorized to perform an action when processing attacker-supplied ...
CVE-2026-5192
- EPSS 0.77%
- Veröffentlicht 05.05.2026 06:43:30
- Zuletzt bearbeitet 05.05.2026 19:08:20
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.52.1 via the 'upload-1[file][file_path]' parameter. This makes it possible for unauthenti...
CVE-2026-2002
- EPSS 0.15%
- Veröffentlicht 17.02.2026 04:35:45
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form_name parameter in all versions up to, and including, 1.50.2 due to insufficient input sanitization ...
CVE-2025-14782
- EPSS 0.26%
- Veröffentlicht 09.01.2026 06:34:53
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.49.1 via the 'listen_for_csv_export' function. This is due to the plugin not pr...
CVE-2025-7638
- EPSS 0.29%
- Veröffentlicht 18.07.2025 04:23:01
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and including, 1.45.0 due to insufficient escaping on the user ...
CVE-2025-6464
- EPSS 0.47%
- Veröffentlicht 02.07.2025 05:29:17
- Zuletzt bearbeitet 07.07.2025 14:22:31
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via deserialization of untrusted input in the 'entry_delete_upload_files' ...
CVE-2025-6463
- EPSS 10.54%
- Veröffentlicht 02.07.2025 04:24:56
- Zuletzt bearbeitet 07.07.2025 14:28:51
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'entry_delete_upload_files' function in all versions up to, and incl...
CVE-2025-5341
- EPSS 0.23%
- Veröffentlicht 05.06.2025 11:15:06
- Zuletzt bearbeitet 10.07.2025 14:40:42
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id' and 'data-size’ parameters in all versions up to, and including, 1.44.1 due to insufficient input s...