Description
The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail configuration to any address, carrying a link of their choosing inside the site's own template. The token that authorises the send is handed to the anonymous caller by the Forminator Forms WordPress plugin before 1.57.2.1 itself and can be replayed without limit.
Published: 2026-09-23
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated email injection enabling arbitrary recipients and attacker‑controlled links
Action: Immediate Patch
AI Analysis

Impact

This flaw resides in the Forminator Forms WordPress plugin before version 1.57.2.1, where the system does not associate a draft email notification with the visitor who created it. An unauthenticated user can supply both the recipient address and a custom link in the request, causing the plugin to send an email using the site's mail configuration to any address of the attacker’s choice. The token that authorises the send is returned to the anonymous caller and may be replayed without limit, meaning the exploit can be repeated indefinitely without authentication. The result is the ability to spam or phish from the site’s domain without needing user credentials.

Affected Systems

WordPress installations running the Forminator Forms plugin with a version earlier than 1.57.2.1 are vulnerable. The issue affects the plugin itself; specific vendor or product names are limited to the plugin’s generic identifier.

Risk and Exploitability

The CVSS score of 3.7 indicates moderate severity, and the EPSS of less than 1% suggests that exploitation is unlikely to be widely observed at present. Although the vulnerability is not listed in the CISA KEV catalog, the lack of authentication requirement combined with the unlimited replayability of the token means an attacker who discovers the endpoint could easily construct malicious emails. The primary attack vector is via form submissions that are publicly accessible to unauthenticated users.

Generated by OpenCVE AI on September 23, 2026 at 14:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Forminator Forms plugin to version 1.57.2.1 or later, which binds notifications to the originating user and removes the token replayability.
  • If an upgrade cannot be performed immediately, disable or remove the Forminator Forms plugin from the WordPress installation until a patch is applied.
  • Implement a Web Application Firewall or rate‑limiting rules that restrict POST requests to the form submission endpoint, reducing the chance of automated exploitation.

Generated by OpenCVE AI on September 23, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail configuration to any address, carrying a link of their choosing inside the site's own template. The token that authorises the send is handed to the anonymous caller by the Forminator Forms WordPress plugin before 1.57.2.1 itself and can be replayed without limit.
Title Forminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sending with Attacker-Controlled Link
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T10:54:24.744Z

Reserved: 2026-09-08T19:05:47.054Z

Link: CVE-2026-87074

cve-icon Vulnrichment

Updated: 2026-09-23T10:34:50.600Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:04.557

Modified: 2026-09-23T11:17:15.593

Link: CVE-2026-87074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:30:06Z

Weaknesses