Sceawere

Vulnerability Detail

CVE-2026-106611UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Forminator CSRF Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
4h ago
Vendor
WPMU DEV
Product
Forminator
Attack Type
Cross-Site Request Forgery (CSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Forminator forminator allows Cross Site Request Forgery.This issue affects Forminator: from n/a through 1.57.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-08T13:17:15.013Z",
  "pubdate": "2026-10-08T13:17:15.013Z",
  "executiveSummary": "The WPMU DEV Forminator plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This security flaw allows an unauthenticated or authenticated attacker to coerce a victim into performing unintended actions within the application without their consent.\nThe vulnerability resides within the application's request handling mechanism, which fails to adequately validate the legitimacy of incoming requests. By enticing a privileged user to interact with a malicious link or site, an attacker can execute unauthorized operations on the Forminator plugin's backend configurations or form data processing.\nThe scope of impact includes unauthorized administrative changes, data manipulation, or potentially the execution of sensitive actions under the victim's session. The affected versions range from n/a through 1.57.3. Exploitation relies on the victim's active session, making it a significant concern for administrative integrity. Organizations using the specified versions of Forminator are at risk of unauthorized state-changing operations being performed on their WordPress instance.",
  "technicalDetails": "The vulnerability is a Cross-Site Request Forgery (CSRF) residing in the WPMU DEV Forminator plugin for WordPress. The flaw exists because the plugin's administrative and configuration interfaces fail to implement robust anti-CSRF tokens (nonces) or perform strict HTTP Referer/Origin header validation for sensitive state-changing requests. As a result, the application cannot distinguish between a legitimate request initiated by an authorized administrator and a forged request initiated by an attacker.\nThe exploitation flow begins when an attacker identifies a sensitive action within the Forminator plugin that results in a state change—such as updating form settings, modifying submission handling configurations, or altering integration endpoints. The attacker then crafts a malicious HTML page or script designed to execute an HTTP request (typically a POST request) targeting the vulnerable endpoint on the victim's WordPress site.\nThe attacker baits an authenticated administrator into navigating to the malicious page. Once the victim loads the page, the attacker's script automatically triggers the forged request to the vulnerable Forminator component. Because the victim maintains an active authenticated session with the WordPress administrative dashboard, the browser automatically attaches the necessary session cookies to the forged request. The server, lacking proper CSRF protection, processes the request as if it were a legitimate administrative action.\nThe root cause is the absence of cryptographically secure, per-request or per-session tokens that should be checked by the server before executing the action. Without these tokens, the application is fundamentally unable to verify intent.\nAffected versions of Forminator span from the initial release through version 1.57.3. The vulnerability is accessible over the network via standard web protocols (HTTP/HTTPS). Successful exploitation depends on the victim having sufficient privileges to perform the targeted action. Post-exploitation impact varies depending on the targeted function, but may involve unauthorized modification of form data, injection of malicious scripts into form fields, or subversion of plugin configurations, potentially leading to further compromise of the WordPress environment."
}
CVE-2026-106611: Forminator CSRF Vulnerability (HIGH Severity, CVSS: 7.1) | Sceawere