VYPR

Forminator

by WordPress

Source repositories

CVEs (35)

  • CVE-2026-82220MedAug 28, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.

  • CVE-2026-6222MedMay 7, 2026
    risk 0.34cvss 5.3epss 0.00

    The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method in `Forminator_Admin_Module_Edit_Page` (admin/abstracts/class-admin-module-edit-page.php) dispatching sensitive…

  • CVE-2026-32409MedMar 13, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Forminator: from n/a through <= 1.50.2.

  • CVE-2025-7638MedJul 18, 2025
    risk 0.32cvss 4.9epss 0.00

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and including, 1.45.0 due to insufficient escaping on the user supplied parameter and lack…

  • CVE-2023-5119MedNov 20, 2023
    risk 0.31cvss 4.8epss 0.00

    The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed…

  • CVE-2021-24700MedNov 23, 2021
    risk 0.31cvss 4.8epss 0.01

    The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

  • CVE-2021-4417MedJul 12, 2023
    risk 0.28cvss 5.4epss 0.00

    The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.13.4. This is due to missing or incorrect nonce validation on the listen_for_saving_export_schedule()…

  • CVE-2026-2729MedMay 5, 2026
    risk 0.27cvss 5.3epss 0.00

    The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. This is due to the plugin not properly verifying that a user is authorized to perform an action when processing attacker-supplied Stripe PaymentIntent…

  • CVE-2025-14782MedJan 9, 2026
    risk 0.27cvss 5.3epss 0.00

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.49.1 via the 'listen_for_csv_export' function. This is due to the plugin not properly verifying that a…

  • CVE-2025-3479MedApr 17, 2025
    risk 0.27cvss 5.3epss 0.00

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 1.42.0 via the 'handle_stripe_single' function due to insufficient validation on a user controlled key. This makes…

  • CVE-2024-9352MedOct 17, 2024
    risk 0.21cvss 4.3epss 0.00

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.35.1. This is due to missing or incorrect nonce validation on the custom form 'create_module'…

  • CVE-2023-2010LowJul 4, 2023
    risk 0.20cvss 3.1epss 0.00

    The Forminator WordPress plugin before 1.24.1 does not use an atomic operation to check whether a user has already voted, and then update that information. This leads to a Race Condition that may allow a single user to vote multiple times on a poll.

  • CVE-2026-57815HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Path Traversal.This issue affects Forminator: from n/a through <= 1.55.0.2.

  • CVE-2026-57814HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows DOM-Based XSS.This issue affects Forminator: from n/a through <= 1.55.0.1.

  • CVE-2026-56071HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.

Page 2 of 2