Sceawere

Vulnerability Detail

CVE-2026-12998UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Forminator Forms IDOR Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
wpmudev
Product
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the 'draft' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate sequential integer entry IDs via the 'draft' parameter and read other users' saved draft form data, including names, email addresses, phone numbers, addresses, and free-form message content. This is only exploitable on forms that have the 'Save and Continue' feature enabled.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-16T07:16:30.173Z",
  "pubdate": "2026-08-16T07:16:30.173Z",
  "executiveSummary": "An Insecure Direct Object Reference (IDOR) vulnerability exists in the Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress in all versions up to, and including, 1.55.0.2. The vulnerability arises due to missing validation on a user-controlled key via the 'draft' parameter.\nThis flaw allows unauthenticated threat actors to enumerate sequential integer entry IDs by manipulating the 'draft' parameter. Consequently, unauthorized individuals can read sensitive draft form data belonging to other users, including personally identifiable information such as names, email addresses, phone numbers, physical addresses, and free-form message content.\nThe risk implications are significant, as data exposure can lead to privacy violations and potential social engineering attacks leveraging harvested user details. Successful exploitation requires the targeted forms to have the 'Save and Continue' feature explicitly enabled. The attack can be executed remotely over the network without requiring any authentication or prior privileges on the target WordPress installation.",
  "technicalDetails": "The root cause of this vulnerability is an Insecure Direct Object Reference (IDOR) stemming from the lack of proper authorization checks and input validation on user-controlled keys within the Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin. Specifically, the flaw resides in the handling of the 'draft' parameter, which manages the retrieval of saved form data.\nThe affected component is utilized when forms have the 'Save and Continue' feature enabled. In this state, the application processes sequential integer entry IDs passed via the 'draft' parameter to fetch previously saved user sessions. Because the software fails to cryptographically randomize these identifiers or validate that the requesting entity owns or is authorized to access the specific session, the parameter becomes susceptible to enumeration.\nThe attack flow proceeds as follows: an unauthenticated attacker identifies a WordPress target running a vulnerable version of the Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin where the 'Save and Continue' functionality is active. The attacker crafts HTTP requests containing the 'draft' parameter and systematically iterates through sequential integer values representing entry IDs. Since the backend application logic processes these requests without verifying session ownership or access permissions, it responds by returning the associated saved draft form data.\nThe payload behavior involves probing the endpoint with predictable numerical values. Post-exploitation impact includes the unauthorized disclosure of sensitive data submitted by users before form completion. Exposed information encompasses names, email addresses, phone numbers, physical addresses, and free-form message contents. The vulnerability is exploitable remotely over the network, requires zero authentication, and demands no special user privileges."
}
CVE-2026-12998: Forminator Forms IDOR Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere