Description
Unauthenticated Arbitrary Content Deletion in Forminator <= 1.57.3 versions.
Published: 2026-10-10
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized Content Deletion
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated attacker can delete arbitrary content in WordPress sites that have the Forminator plugin installed in version 1.57.3 or earlier. The vulnerability allows the removal of posts, pages, or other content without requiring any user privileges, leading to loss of data and potential disruption of site functionality. The weakness is rooted in missing authentication checks on deletion actions, mapping to CWE‑862.

Affected Systems

The flaw affects sites running the WPMU DEV Forminator plugin at version 1.57.3 or earlier. Users should verify the plugin version and upgrade promptly because the issue is present across all affected releases of that plugin by that vendor.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating high severity. Although the EPSS score is not available, the lack of authentication checks suggests that exploitation could be straightforward if the attacker can reach the site. The vulnerability is not currently listed in the CISA KEV catalog, but site owners should treat it as high risk due to potential data loss. Protective measures rely on ensuring only authenticated privileged users can trigger deletion operations.

Generated by OpenCVE AI on October 10, 2026 at 21:26 UTC.

Remediation

Vendor Solution

Update the WordPress Forminator plugin to the latest available version (at least 1.58.0).


OpenCVE Recommended Actions

  • Upgrade the Forminator plugin to version 1.58.0 or later to apply the vendor‑provided fix.
  • Limit or disable guest access to forms that expose deletion functionality, ensuring only authenticated users can trigger deletions.
  • Regularly back up WordPress content so that accidental or malicious deletions can be restored.

Generated by OpenCVE AI on October 10, 2026 at 21:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Arbitrary Content Deletion in Forminator <= 1.57.3 versions.
Title WordPress Forminator plugin <= 1.57.3 - Arbitrary Content Deletion vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:36:06.909Z

Reserved: 2026-07-22T08:53:17.417Z

Link: CVE-2026-65459

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:45.117

Modified: 2026-10-10T20:16:45.117

Link: CVE-2026-65459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T21:30:17Z

Weaknesses