Impact
The Forminator Forms WordPress plugin, before version 1.57.2.1, fails to validate the classes that may be instantiated during deserialization of a value received through an XML‑RPC request. An attacker who has the forms‑management permission can supply a crafted payload that writes a file of their choice and causes the site to execute that payload. The result is that the attacker can run arbitrary server‑side code with the privileges of the user holding that permission. This produces a classic remote‑code‑execution vulnerability.
Affected Systems
Any WordPress installation that uses the Forminator Forms plugin with a version earlier than 1.57.2.1 is affected. The vulnerability is tied to the plugin's form‑management permission, which by default is granted to administrators and can be granted to lower‑privilege roles via the plugin’s configuration. Therefore, sites that have enabled XML‑RPC and assign a non‑administrator role the forms‑management capability are also at risk.
Risk and Exploitability
Based on the plugin’s handling of XML‑RPC requests, the likely attack vector is a network‑based request to the XML‑RPC endpoint, potentially reachable from the public internet. The CVE has a CVSS score of 8.5 and an EPSS score of less than 1%, and is not listed in CISA's KEV catalog. Attackers must be authenticated and possess form‑management rights; however, those rights are normally held by admins and may be granted to regular users on sites that misuse the plugin’s settings. Because the plugin processes XML‑RPC requests that are commonly enabled on WordPress sites, the vulnerability can be reached from the public internet as long as the target site uses XML‑RPC. The lack of publicly disclosed exploitation details suggests that the likelihood of active exploitation may be limited at present, but the potential impact—remote code execution—is severe.
OpenCVE Enrichment