Impact
The Forminator Forms plugin for WordPress allows unauthenticated attackers to supply an unvalidated 'current_url' parameter that is passed directly to WordPress's do_shortcode function. This flaw permits the execution of arbitrary shortcodes, which could carry out any action implemented by a shortcode, including data manipulation or site defacement. The vulnerability is categorized as CWE-94.
Affected Systems
All WordPress sites that install the Forminator Forms plugin version 1.57.2 or earlier are affected, including those using the contact, payment, or custom form modules supplied by WPMU DEV.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.1, indicating critical severity. EPSS data is not available, and the flaw is not yet listed on the CISA KEV catalogue. An attacker can reach the flaw from any public URL containing a malicious 'current_url' value, without needing authentication, by leveraging the lack of input validation before invoking do_shortcode. Because the plugin is widely deployed, the potential impact on affected sites is significant, although current exploitation activity is unknown due to missing EPSS information.
OpenCVE Enrichment