rootpwn

critical · CVSS v3 9.1 · EPSS 0.00402

CVE-2026-92229

The Forminator Forms plugin for WordPress contains an arbitrary shortcode execution vulnerability affecting versions up to 1.57.2. The issue

Overview

The Forminator Forms plugin for WordPress contains an arbitrary shortcode execution vulnerability affecting versions up to 1.57.2. The issue stems from insufficient validation of user-supplied values prior to executing the do_shortcode function. This flaw allows unauthenticated remote attackers to execute arbitrary shortcodes within the application context.

Description

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Impact

Unauthenticated attackers can leverage this vulnerability to execute arbitrary shortcodes, potentially leading to information disclosure, remote code execution depending on registered shortcodes, or further compromise of the WordPress site. Confidentiality, integrity, and availability of the affected WordPress site are at risk. Site administrators and users relying on the Forminator Forms plugin are directly impacted.

Remediation

Update the Forminator Forms plugin to version 1.57.3 or later immediately to patch the validation flaw. Review site logs for suspicious unauthenticated requests targeting plugin endpoints. Implement Web Application Firewall (WAF) rules to detect and block malicious shortcode injection attempts.

Risk context

Rated as a critical severity vulnerability with a CVSS score of 9.1, indicating a severe risk to affected installations. The EPSS score of 0.00402 reflects a currently low observed exploitation probability in the wild, but the high severity warrants prompt patching due to the unauthenticated nature of the flaw.

Affected products

  • WPMU DEV Forminator Forms
  • WordPress plugin

Scores

Severity
critical
CVSS v2
9.4
CVSS v3
9.1
CVSS v4
EPSS
0.00402

cve wordpress plugin forminator-forms shortcode-execution unauthenticated critical

← All CVEs