Description
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Forminator Forms WordPress plugin before 1.57.2.1's own settings, so the issue is reachable well below administrator on sites that use that feature.
Published: 2026-09-20
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Forminator Forms WordPress plugin, before version 1.57.2.1, fails to validate the classes that may be instantiated during deserialization of a value received through an XML‑RPC request. An attacker who has the forms‑management permission can supply a crafted payload that writes a file of their choice and causes the site to execute that payload. The result is that the attacker can run arbitrary server‑side code with the privileges of the user holding that permission. This produces a classic remote‑code‑execution vulnerability.

Affected Systems

Any WordPress installation that uses the Forminator Forms plugin with a version earlier than 1.57.2.1 is affected. The vulnerability is tied to the plugin's form‑management permission, which by default is granted to administrators and can be granted to lower‑privilege roles via the plugin’s configuration. Therefore, sites that have enabled XML‑RPC and assign a non‑administrator role the forms‑management capability are also at risk.

Risk and Exploitability

Based on the plugin’s handling of XML‑RPC requests, the likely attack vector is a network‑based request to the XML‑RPC endpoint, potentially reachable from the public internet. The CVE has a CVSS score of 8.5 and an EPSS score of less than 1%, and is not listed in CISA's KEV catalog. Attackers must be authenticated and possess form‑management rights; however, those rights are normally held by admins and may be granted to regular users on sites that misuse the plugin’s settings. Because the plugin processes XML‑RPC requests that are commonly enabled on WordPress sites, the vulnerability can be reached from the public internet as long as the target site uses XML‑RPC. The lack of publicly disclosed exploitation details suggests that the likelihood of active exploitation may be limited at present, but the potential impact—remote code execution—is severe.

Generated by OpenCVE AI on September 20, 2026 at 17:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Forminator Forms plugin to version 1.57.2.1 or later.
  • Revoke or limit the forms‑management permission to only trusted administrators or roles explicitly needing it.
  • If XML‑RPC is not required for your site’s functionality, disable the XML‑RPC endpoint or restrict it to trusted hosts.

Generated by OpenCVE AI on September 20, 2026 at 17:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions forminator Forms
Vendors & Products Wordpress-extensions
Wordpress-extensions forminator Forms

Sun, 20 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Forminator Forms WordPress plugin before 1.57.2.1's own settings, so the issue is reachable well below administrator on sites that use that feature.
Title Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection
References

Subscriptions

Wordpress-extensions Forminator Forms
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-20T13:49:48.471Z

Reserved: 2026-09-08T19:01:39.377Z

Link: CVE-2026-87067

cve-icon Vulnrichment

Updated: 2026-09-20T13:49:29.532Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T07:16:50.430

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-87067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:48:42Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')