Impact
The Forminator Forms plugin suffers from an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to craft a 'draft' parameter value and read other users' saved draft form data, which may include names, email addresses, phone numbers, addresses, and free‑form messages. This flaw arises from missing validation on a user controlled key, enabling enumeration of sequential integer entry IDs and the exposure of personally identifiable information. The primary impact is the disclosure of sensitive user data without authorization.
Affected Systems
The vulnerability affects the wpmudev:Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress in all releases up to and including version 1.55.0.2. It is only exploitable on forms that have the 'Save and Continue' feature enabled, as that feature stores draft data retrieved via the vulnerable 'draft' parameter.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity; the EPSS score is not available and the issue is not listed in the CISA KEV catalog, suggesting it is not a high‑profile exploit currently. An attacker requires only unauthenticated access to a WordPress site with the plugin installed, and can systematically enumerate integer entry IDs through the 'draft' parameter to obtain draft data. Although the risk is not critical, the potential exposure of personal data warrants prompt remediation.
OpenCVE Enrichment