CVE-2026-2729: Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.52.0 - Missing Authorization to Unauthenticated Stripe PaymentIntent Reuse / Underpayment Bypass via 'paymentid' Parameter
The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. This is due to the plugin not properly verifying that a user is authorized to perform an action when processing attacker-supplied Stripe PaymentIntent identifiers in the public payment flow. This makes it possible for unauthenticated attackers to submit high-value paid forms as completed by reusing a previously succeeded low-value Stripe PaymentIntent, resulting in underpayment/payment bypass conditions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2729?
CVE-2026-2729 is considered a high severity vulnerability due to its potential for unauthorized payment processing.
How do I fix CVE-2026-2729?
To fix CVE-2026-2729, update the Forminator plugin to version 1.53.0 or later.
What can attackers do with CVE-2026-2729?
Attackers can exploit CVE-2026-2729 to bypass authorization checks and reuse payment intents, leading to unauthorized transactions.
Which versions of Forminator are affected by CVE-2026-2729?
CVE-2026-2729 affects all versions of the Forminator plugin up to and including version 1.52.0.
Is authentication required to exploit CVE-2026-2729?
No, CVE-2026-2729 can be exploited by unauthenticated users due to missing authorization checks.