CVE-2026-92229: The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcod…
CVSS 9.1 · EPSS 0.4%
https://beta.vulnsea.com/cve/CVE-2026-92229
#CVE #infosec #cybersecurity #threatintel
CVE-2026-92229: The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcod…
CVSS 9.1 · EPSS 0.4%
https://beta.vulnsea.com/cve/CVE-2026-92229
#CVE #infosec #cybersecurity #threatintel
51 patched vulnerabilities and counting: one popular WordPress plugin's history shows why "just keep updating" isn't enough anymore.
#hackernews #news
51 patched vulnerabilities and counting: one popular WordPress plugin's history shows why "just keep updating" isn't enough anymore.
#hackernews #news
WordPressプラグイン「Yo」「Forminator Forms」「SAML Single Sign On」に深刻な脆弱性が見つかりました。サイトへの影響と対策を1分で確認しましょう。
WordPressプラグイン「Yo」「Forminator Forms」「SAML Single Sign On」に深刻な脆弱性が見つかりました。サイトへの影響と対策を1分で確認しましょう。
📊 5.3/10
🏢 Unknown
📝 The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwardin...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85191
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 Unknown
📝 The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwardin...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85191
#cybersecurity #infosec #cve #euvd
In-page form that uses the fonts, colors and theme of the page itself! Doofenschmirtz's Forminator works!
Before I can USE it, tho, I still need to contact WordPress support and figure out why their SMTP email system isn't talking with my mail provider
In-page form that uses the fonts, colors and theme of the page itself! Doofenschmirtz's Forminator works!
Before I can USE it, tho, I still need to contact WordPress support and figure out why their SMTP email system isn't talking with my mail provider
📊 n/a
🏢 Unknown
📝 The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migrat...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85047
#cybersecurity #infosec #cve #euvd
📊 n/a
🏢 Unknown
📝 The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migrat...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85047
#cybersecurity #infosec #cve #euvd
📊 n/a
🏢 Unknown
📝 The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the re...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85048
#cybersecurity #infosec #cve #euvd
📊 n/a
🏢 Unknown
📝 The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the re...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85048
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 Unknown
📝 The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys Wo...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85192
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 Unknown
📝 The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys Wo...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85192
#cybersecurity #infosec #cve #euvd
patchstack.com/database/wor...
#WordPress #WordPressSecurity
patchstack.com/database/wor...
#WordPress #WordPressSecurity