CVE-2026-92229: Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running doshortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker does not need to authenticate to exploit it. The supplied vector is network-accessible, requires low attack complexity, and does not require user interaction.
Which installations are affected?
Forminator Forms versions through 1.57.2, including 1.57.2, are affected according to the provided information. No fixed version is identified in the data.
What is the likely impact of successful exploitation?
A successful attacker can execute arbitrary shortcodes. The vulnerability is rated critical with high confidentiality and integrity impact, while availability impact is listed as none.