#Forminator
Han trobat una de les portes del darrera que l’NSA portava anys fent servir, toca tancar-la XD.
September 25, 2026 at 7:35 PM
Das ganze Problem bei diesen undichten WordPress-Plugins ist neben der KI, die solche Lücken immer schneller entdeckt, auch der Irrglaube, dass diese Plugins von seriösen Firmen professionell entwickelt werden.
Critical Vulnerability in Forminator Plugin Allows Unauthenticated RCE – The Daily Tech Feed
thedailytechfeed.com
August 17, 2026 at 6:50 PM
Nah, it's called "Forminator". Fuckin Doofenschmirtz-ass name lmao
August 20, 2026 at 2:28 AM
51 patched vulnerabilities and counting: one popular WordPress plugin's history shows why "just keep updating" isn't enough anymore. #wordpress
Another Day, Another WordPress Hole: Forminator Joins The Security Merry-Go-Round
hackernoon.com
September 22, 2026 at 1:01 PM
Forminator has a high-severity, unauthenticated shortcode execution flaw requiring urgent updates, reflecting a long pattern of frequent critical plugin vulnerabilities.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 22, 2026 at 4:15 PM
The Forminator plugin for WordPress is vulnerable to an unauthenticated arbitrary file deletion flaw that could enable full site takeover attacks.
Forminator plugin flaw exposes WordPress sites to takeover attacks
The Forminator plugin for WordPress is vulnerable to an unauthenticated arbitrary file deletion flaw that could enable full site takeover attacks.
www.bleepingcomputer.com
July 2, 2025 at 3:38 PM
Had mad issues with reCaptcha on our WordPress site, so shifted from Elementor forms to implementing all site forms in Forminator with honeypot + Akismet spam protection. Also added more form fields to make them less automatable.
August 5, 2025 at 4:42 AM
CVE-2026-92229 Forminator Forms WordPress plugin, CVSS 9.1. Unauthenticated attackers can run arbitrary shortcodes on all versions up to 1.57.2. No patch yet. Disable the plugin or restrict access now. https://www.valtersit.com/cve/CVE-2026-92229/ #CVE #WordPress #infosec
CVE-2026-92229 Vulnerability in Forminator Forms – Contact Form, Payment Form & Custom Form Builder
www.valtersit.com
September 23, 2026 at 7:00 PM
Forminator WordPress Plugin Vulnerability Exposes 400,000 Websites to Takeover - SecurityWeek buff.ly/sXCS2KS
Forminator WordPress Plugin Vulnerability Exposes 400,000 Websites to Takeover
A vulnerability in the Forminator WordPress plugin allows attackers to delete arbitrary files and take over impacted websites.
buff.ly
July 6, 2025 at 2:42 PM
🌊 ABYSSAL · critical with a public exploit
CVE-2026-92229: The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcod…
CVSS 9.1 · EPSS 0.4%
https://beta.vulnsea.com/cve/CVE-2026-92229

#CVE #infosec #cybersecurity #threatintel
CVE-2026-92229 — The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to e…
beta.vulnsea.com
September 20, 2026 at 6:24 PM
Eine hochriskante Sicherheitslücke im 600.000 Mal installierten WordPress-Plug-in Forminator ermöglicht volle Kompromittierung. #Security
600.000 WordPress-Instanzen durch Lücke in Plug-in Forminator kompromittierbar
Eine hochriskante Sicherheitslücke im 600.000 Mal installierten WordPress-Plug-in Forminator ermöglicht volle Kompromittierung.
www.heise.de
July 2, 2025 at 10:17 AM
Another Day, Another WordPress Hole: Forminator Joins The Security Merry-Go-Round

51 patched vulnerabilities and counting: one popular WordPress plugin's history shows why "just keep updating" isn't enough anymore.
#hackernews #news
Another Day, Another WordPress Hole: Forminator Joins The Security Merry-Go-Round
51 patched vulnerabilities and counting: one popular WordPress plugin's history shows why "just keep updating" isn't enough anymore.
hackernoon.com
September 23, 2026 at 7:28 AM
Prawdziwy ... forminator 😁
April 6, 2026 at 9:24 AM
Forminator has a high-severity, unauthenticated shortcode execution flaw requiring urgent updates, reflecting a long pattern of frequent critical plugin vulnerabilities.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 22, 2026 at 4:14 PM
【2026年09月21日】WordPress プラグイン脆弱性まとめ: Yo、Forminator Forms など 3 件

WordPressプラグイン「Yo」「Forminator Forms」「SAML Single Sign On」に深刻な脆弱性が見つかりました。サイトへの影響と対策を1分で確認しましょう。
【2026年09月21日】WordPress プラグイン脆弱性まとめ: Yo、Forminator Forms など 3 件
WordPressプラグイン「Yo」「Forminator Forms」「SAML Single Sign On」に深刻な脆弱性が見つかりました。サイトへの影響と対策を1分で確認しましょう。
wp-vuln.devops-digest.com
September 21, 2026 at 6:49 AM
Forminator has a high-severity, unauthenticated shortcode execution flaw requiring urgent updates, reflecting a long pattern of frequent critical plugin vulnerabilities.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 22, 2026 at 4:19 PM
🚨 EUVD-2026-85191
📊 5.3/10
🏢 Unknown

📝 The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwardin...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85191

#cybersecurity #infosec #cve #euvd
September 23, 2026 at 11:01 AM
Update: It works!

In-page form that uses the fonts, colors and theme of the page itself! Doofenschmirtz's Forminator works!

Before I can USE it, tho, I still need to contact WordPress support and figure out why their SMTP email system isn't talking with my mail provider
Heinz Doofenshmirtz Content
ALT: Heinz Doofenshmirtz Content
static.klipy.com
August 20, 2026 at 3:49 AM
🚨 EUVD-2026-85047
📊 n/a
🏢 Unknown

📝 The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migrat...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85047

#cybersecurity #infosec #cve #euvd
September 23, 2026 at 7:02 AM
🚨 EUVD-2026-85192
📊 5.3/10
🏢 Unknown

📝 The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys Wo...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85192

#cybersecurity #infosec #cve #euvd
September 23, 2026 at 11:01 AM
Forminator Forms CRITICAL vuln (CVE-2026-87068): Users with quiz import rights can create forms granting admin roles. Affects v1.57.0 – <1.57.2.1. Update to 1.57.2.1+ now. 🔒 https://radar.offseq.com/threat/cve-2026-87068-cwe-269-improper-privilege-management-in-forminator-forms-d94f6ced78eef6c1 #...
CVE-2026-87068: CWE-269 Improper Privilege Management in Forminator Forms
CVE-2026-87068 is an improper privilege management vulnerability (CWE-269) in the Forminator Forms WordPress plugin before version 1.57.2.1. The plugin fails to enforce role validation when a registration form is nested inside an imported q
radar.offseq.com
September 20, 2026 at 7:30 AM
🚨 EUVD-2026-85048
📊 n/a
🏢 Unknown

📝 The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the re...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85048

#cybersecurity #infosec #cve #euvd
September 23, 2026 at 7:02 AM
Das WordPress-Plug-in Forminator Forms enthält eine kritische Schadcode-Lücke. Zudem sind Royal Elementor Addons löchrig. #Security
WordPress-Plug-in Forminator Forms: Kritische Lücke erlaubt Codeschmuggel
Das WordPress-Plug-in Forminator Forms enthält eine kritische Schadcode-Lücke. Zudem sind Royal Elementor Addons löchrig.
www.heise.de
August 18, 2026 at 6:13 AM
Forminator Forms ≤1.57.2 has an unauthenticated shortcode-execution hole (CVE-2026-92229). If you run quizzes or forms with it, update to 1.57.3 now. No login needed for the bad request.

patchstack.com/database/wor...

#WordPress #WordPressSecurity
September 21, 2026 at 2:17 PM