CVE-2026-66583: WordPress Forminator plugin <= 1.57.0 - PHP Object Injection vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
Affected Software
1 affected component
WordPress Forminator<=1.57.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Forminatorto a version that resolves this vulnerability.Fixed in 1.57.1
Event History
Aug 20, 2026
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation.
2
Which installations are affected?
WordPress sites using the Forminator plugin version 1.57.0 or earlier are affected according to the available data.