Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Path Traversal.This issue affects Forminator: from n/a through <= 1.55.0.2.
Published: 2026-07-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a Path Traversal flaw (CWE‑22) that permits an attacker to construct a request to the Forminator plugin and download any file located on the server’s filesystem. The flaw enables the retrieval of files located outside the intended directory, potentially exposing confidential data such as configuration files or credentials.

Affected Systems

All WordPress sites running the Forminator plugin from WPMU DEV – Your All‑In‑One WordPress Platform, versions up to and including 1.55.0.2. Any installation of this plugin, regardless of the WordPress core or other plug‑in configuration, is affected.

Risk and Exploitability

The CVSS score of 7.5 classifies while the EPSS score of less than 1% indicates a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalogue, so no confirmed exploitation is known. Exploitation would involve a simple crafted HTTP request to a file‑download endpoint, and based on the description, it is inferred that no special privileges or authentication appear to be required.

Generated by OpenCVE AI on August 1, 2026 at 10:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Forminator plugin to a version 2 (for example 1.55.0.3 or later) where the path‑validation logic has been fixed.
  • If an immediate update is not possible, disable or delete the Forminator plugin to remove the vulnerable endpoint from the site.
  • Apply web‑server controls, such as .htaccess deny rules or firewall filters, to block direct access to the plugin’s file‑download URLs and restrict file serving to legitimate directories only.

Generated by OpenCVE AI on August 1, 2026 at 10:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpmu Dev - Your All-in-one Wordpress Platform
Wpmu Dev - Your All-in-one Wordpress Platform forminator
Vendors & Products Wordpress
Wordpress wordpress
Wpmu Dev - Your All-in-one Wordpress Platform
Wpmu Dev - Your All-in-one Wordpress Platform forminator

Mon, 13 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Path Traversal.This issue affects Forminator: from n/a through <= 1.55.0.2.
Title WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wordpress Wordpress
Wpmu Dev - Your All-in-one Wordpress Platform Forminator
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T10:25:20.611Z

Reserved: 2026-06-25T08:05:16.224Z

Link: CVE-2026-57815

cve-icon Vulnrichment

Updated: 2026-07-13T10:25:14.674Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:30:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')