Sceawere

Vulnerability Detail

CVE-2026-82220UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Forminator Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
5h ago
Vendor
WPMU DEV
Product
Forminator
Attack Type
CWE-294 Authentication Bypass by Capture-replay
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-28T16:18:31.937Z",
  "pubdate": "2026-08-28T16:18:31.937Z",
  "executiveSummary": "The Forminator plugin for WordPress, in all versions up to and including 1.57.1, contains an unauthenticated vulnerability classified as 'Other Vulnerability Type'.\nThis vulnerability allows an unauthenticated remote attacker to interact with the plugin’s functionality without prior authorization or established session tokens.\nThe lack of adequate access control mechanisms at the entry point of the affected component exposes the application to unauthorized operations.\nThe impact depends on the specific functions triggered by this flaw, which may lead to unauthorized data retrieval, unauthorized configuration changes, or the manipulation of form processing workflows.\nBecause the vulnerability is exploitable by unauthenticated users, it presents a significant risk to site integrity and confidentiality, as no prior authentication or administrative privileges are required to initiate the attack.\nSystems running Forminator versions 1.57.1 or earlier are exposed to this risk until they are updated to a patched release. No complex interaction or specific user behavior is required to trigger the exploit, facilitating automated exploitation attempts by malicious actors.",
  "technicalDetails": "The vulnerability resides within the request handling architecture of the Forminator plugin. The root cause is identified as an insufficient authorization check during the processing of incoming requests to the plugin's internal API or action handlers.\nIn versions 1.57.1 and earlier, the affected component fails to validate the identity or authorization context of the user before executing certain operations. This flaw bypasses security gates that are intended to restrict plugin configuration or data handling tasks to authenticated administrative users.\nThe exploitation flow begins when an unauthenticated actor sends a crafted HTTP request directly to the Forminator endpoint. Because the plugin does not verify the user's role or session integrity, the request is processed by the backend logic as a legitimate command. Depending on the target function, an attacker could potentially manipulate form submissions, retrieve sensitive form data, or alter the plugin's operational state without needing to authenticate into the WordPress environment.\nThis vulnerability is classified as 'Other' due to the breadth of potential outcomes; because Forminator handles complex data structures, user input, and integration hooks, the absence of an authorization gate means that any function invoked via the plugin's frontend or AJAX hooks can be triggered by an external entity. This bypasses typical WordPress security controls, as the plugin implements its own custom routing for form-related operations.\nThe attack is persistent across the network, as the endpoint is exposed via standard web protocols (HTTP/HTTPS) and does not require local access. The payload behavior is contingent upon the specific function being accessed, but in a standard attack scenario, the attacker would identify the target API endpoint and provide the necessary parameters to induce the desired state change or data exfiltration. Since the vulnerable component does not enforce nonce validation or capability checks, the attacker is effectively able to impersonate an authorized user to the plugin's subsystem.\nPost-exploitation, the impact ranges from loss of data privacy (if form entry data is accessible) to system-level degradation if the attacker can modify site configurations that interact with external services or third-party integrations facilitated by Forminator."
}
CVE-2026-82220: Unauthenticated Forminator Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere