CVE-2026-96335: WordPress Forminator plugin <= 1.57.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Forminator: from n/a through 1.57.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Forminator Forms – Contact Form, Payment Form & Custom Form Builderto a version that resolves this vulnerability.Fixed in 1.57.3
Event History
Frequently Asked Questions
Which Forminator installations are affected?
The issue affects WPMU DEV Forminator versions through 1.57.2. The available data does not identify a fixed version.
Can this be exploited remotely without authentication?
Yes. The CVSS vector indicates network-based exploitation with low complexity, no privileges required, and no user interaction required.
What is the likely security impact?
The supplied severity vector indicates a high integrity impact, with no stated confidentiality or availability impact. The vulnerability is described as broken access control caused by missing authorization and incorrectly configured access-control security levels.