Impact
This flaw resides in the Forminator Forms WordPress plugin before version 1.57.2.1, where the system does not associate a draft email notification with the visitor who created it. An unauthenticated user can supply both the recipient address and a custom link in the request, causing the plugin to send an email using the site's mail configuration to any address of the attacker’s choice. The token that authorises the send is returned to the anonymous caller and may be replayed without limit, meaning the exploit can be repeated indefinitely without authentication. The result is the ability to spam or phish from the site’s domain without needing user credentials.
Affected Systems
WordPress installations running the Forminator Forms plugin with a version earlier than 1.57.2.1 are vulnerable. The issue affects the plugin itself; specific vendor or product names are limited to the plugin’s generic identifier.
Risk and Exploitability
The CVSS score of 3.7 indicates moderate severity, and the EPSS of less than 1% suggests that exploitation is unlikely to be widely observed at present. Although the vulnerability is not listed in the CISA KEV catalog, the lack of authentication requirement combined with the unlimited replayability of the token means an attacker who discovers the endpoint could easily construct malicious emails. The primary attack vector is via form submissions that are publicly accessible to unauthenticated users.
OpenCVE Enrichment