Description
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Published: 2026-09-19
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary shortcode execution
Action: Immediate Patch
AI Analysis

Impact

The Forminator Forms plugin for WordPress allows unauthenticated attackers to supply an unvalidated 'current_url' parameter that is passed directly to WordPress's do_shortcode function. This flaw permits the execution of arbitrary shortcodes, which could carry out any action implemented by a shortcode, including data manipulation or site defacement. The vulnerability is categorized as CWE-94.

Affected Systems

All WordPress sites that install the Forminator Forms plugin version 1.57.2 or earlier are affected, including those using the contact, payment, or custom form modules supplied by WPMU DEV.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.1, indicating critical severity. EPSS data is not available, and the flaw is not yet listed on the CISA KEV catalogue. An attacker can reach the flaw from any public URL containing a malicious 'current_url' value, without needing authentication, by leveraging the lack of input validation before invoking do_shortcode. Because the plugin is widely deployed, the potential impact on affected sites is significant, although current exploitation activity is unknown due to missing EPSS information.

Generated by OpenCVE AI on September 19, 2026 at 10:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Forminator Forms plugin to the latest available version (v1.58 or later) once the vendor releases a fix.
  • If an immediate update is not possible, modify the plugin to sanitize the 'current_url' parameter before it is passed to do_shortcode, or remove the hook that enables arbitrary shortcode execution.
  • Deploy a web application firewall or security plugin that blocks or sanitizes requests containing suspicious 'current_url' values, thereby mitigating the risk of execution.
  • Monitor site logs for unexpected shortcode usage to detect potential exploitation attempts.

Generated by OpenCVE AI on September 19, 2026 at 10:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpmudev
Wpmudev forminator Forms – Contact Form, Payment Form & Custom Form Builder
Vendors & Products Wordpress
Wordpress wordpress
Wpmudev
Wpmudev forminator Forms – Contact Form, Payment Form & Custom Form Builder

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Title Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Wordpress Wordpress
Wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:26.803Z

Reserved: 2026-09-15T18:57:28.835Z

Link: CVE-2026-92229

cve-icon Vulnrichment

Updated: 2026-09-19T13:57:40.848Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T03:17:17.040

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-92229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:45:18Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')