Sceawere

Vulnerability Detail

CVE-2026-96336UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Forminator Identity Spoofing Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
WPMU DEV
Product
Forminator
Attack Type
Authentication Bypass by Spoofing
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Authentication Bypass by Spoofing vulnerability in WPMU DEV Forminator forminator allows Identity Spoofing.This issue affects Forminator: from n/a through 1.57.2.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-09T10:16:44.730Z",
  "pubdate": "2026-10-09T10:16:44.730Z",
  "executiveSummary": "This vulnerability is an authentication bypass via identity spoofing affecting the WPMU DEV Forminator plugin.\nThe flaw allows unauthorized actors to impersonate other users or entities within the form submission process.\nAffected versions range from n/a through 1.57.2.\nThe risk implication is significant as it compromises the integrity and authenticity of data submitted through Forminator forms.\nAn attacker can leverage this vulnerability to bypass standard authentication controls and submit malicious or fraudulent data while appearing as a different, potentially privileged, user.\nThis vulnerability does not appear to require complex exploitation conditions, potentially allowing for remote exploitation by unauthenticated or low-privileged users, depending on the form's configuration.",
  "technicalDetails": "The vulnerability resides within the WPMU DEV Forminator plugin, specifically impacting the logic governing identity verification during form submission processing.\nThe root cause is an improper implementation of identity validation mechanisms, which fails to securely bind a form submission to the authenticated user's session or identity.\nBy manipulating specific parameters within the submission request, an attacker can effectively perform identity spoofing, causing the application to associate the form submission with an identity other than the one intended by the system.\nThe attack flow generally involves the interception or manual crafting of HTTP POST requests destined for the Forminator submission endpoint.\nThe attacker modifies fields responsible for user identification—such as user IDs, email addresses, or session tokens—that the plugin relies upon without adequate server-side validation or cryptographic verification.\nUpon receiving the malformed request, the vulnerable component fails to re-authenticate or verify the authenticity of the claimed identity against the actual session state of the user.\nThis results in the application accepting the submitted data as if it were initiated by the spoofed user entity.\nThe impact of this exploit extends beyond mere data integrity issues; it can facilitate the bypass of access control mechanisms where form submissions trigger downstream actions based on the submitter's identity or role.\nFor instance, if the plugin is configured to grant specific permissions or initiate workflows based on the user submitting the form, an attacker could manipulate these outcomes by spoofing a high-privileged user account.\nFurthermore, this vulnerability allows for the submission of fraudulent data that is cryptographically or logically untraceable to the true source, potentially bypassing audit logs or spam filtering mechanisms that rely on user reputation or identity verification.\nThe vulnerability is present in all versions from n/a up to and including 1.57.2."
}
CVE-2026-96336: Forminator Identity Spoofing Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere