Impact
The vulnerability in the Forminator Forms WordPress plugin exists in all versions older than 1.57.2.1. The plugin trusts client‑supplied forwarding headers without confirming they originate from a trusted proxy, and uses those headers both to enforce a per‑visitor poll vote limit and to record the submitter An unauthenticated visitor can therefore spoof any IP address, submit multiple votes, and set the stored IP to an arbitrary value, corrupting poll results and undermining data integrity.
Affected Systems
Any WordPress installation that uses the Forminator Forms plugin version preceding 1.57.2.1 is affected. Administrators should verify the installed plugin version and update if necessary.
Risk and Exploitability
The CVSS score of 5.3 classifies this as a moderate‑severity flaw, with no EPSS data available and the vulnerability not listed in the CISA KEV catalog. An attacker can exploit the flaw by sending unauthenticated requests that include forged X‑Forwarded‑For style headers, thereby bypassing the poll vote cap and manipulating the recorded IP address with no authentication or additional privileges required.
OpenCVE Enrichment