CVE-2026-15748
- EPSS 1.18%
- Veröffentlicht 18.08.2026 05:31:20
- Zuletzt bearbeitet 20.08.2026 12:48:10
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dange...
CVE-2026-12998
- EPSS 0.3%
- Veröffentlicht 16.08.2026 06:38:07
- Zuletzt bearbeitet 20.08.2026 12:48:10
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the 'draft' parameter due to missing validation on a use...
CVE-2026-18325
- EPSS 0.28%
- Veröffentlicht 06.08.2026 03:26:08
- Zuletzt bearbeitet 12.08.2026 21:00:52
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input...
CVE-2026-6214
- EPSS 0.44%
- Veröffentlicht 07.05.2026 04:16:35
- Zuletzt bearbeitet 07.05.2026 14:00:05
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_for_saving_export_schedule() function in library/class-export.php failing to perform a capability check...
CVE-2026-6222
- EPSS 0.43%
- Veröffentlicht 07.05.2026 01:25:27
- Zuletzt bearbeitet 07.05.2026 14:00:05
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method in `Forminator_Admin_Module_Edit_Page` (admin/abstracts/class-admin-module-edit-page...
CVE-2026-2729
- EPSS 0.37%
- Veröffentlicht 05.05.2026 07:15:59
- Zuletzt bearbeitet 05.05.2026 19:08:20
The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. This is due to the plugin not properly verifying that a user is authorized to perform an action when processing attacker-supplied ...
CVE-2026-5192
- EPSS 0.77%
- Veröffentlicht 05.05.2026 06:43:30
- Zuletzt bearbeitet 05.05.2026 19:08:20
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.52.1 via the 'upload-1[file][file_path]' parameter. This makes it possible for unauthenti...
CVE-2026-2002
- EPSS 0.17%
- Veröffentlicht 17.02.2026 04:35:45
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form_name parameter in all versions up to, and including, 1.50.2 due to insufficient input sanitization ...
CVE-2025-14782
- EPSS 0.27%
- Veröffentlicht 09.01.2026 06:34:53
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.49.1 via the 'listen_for_csv_export' function. This is due to the plugin not pr...
CVE-2025-7638
- EPSS 0.29%
- Veröffentlicht 18.07.2025 04:23:01
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and including, 1.45.0 due to insufficient escaping on the user ...