Impact
The Forminator Forms WordPress plugin before version 1.57.2.1 does not restrict meta keys that may be supplied when a visitor submits a public form. Because the plugin fails to whitelist keys or exclude WordPress‑reserved names, an attacker can inject arbitrary post meta data into the post created by the form. Based on the description, it is inferred that the attack exploits the public form submission endpoint. This flaw results in integrity violations, allowing an attacker to influence how the post is processed or displayed, and may expose sensitive data if the injected keys interact with other plugins or themes.
Affected Systems
Any WordPress installation that uses the Forminator Forms plugin version older than 1.57.2.1 is affected. Sites that expose public forms collecting post content are at particular risk, but the underlying WordPress core is not directly vulnerable unless the injected metadata is processed by another component.
Risk and Exploitability
The CVSS v3 base score of 5.3 indicates medium severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Based on the description, the attack vector is a publicly accessible form submission; no authentication is required, so any visitor can exploit it. The overall risk is moderate, but the lack of authentication allows many potential attackers to submit malicious metadata on high‑traffic sites.
OpenCVE Enrichment