Vulnerability in Forminator Forms – Contact Form, Payment Form & Custom Form Builder — CVE-2026-106611
MediumSeverity
0.1%Estimated exploit probability
600,000+ sitesInstalls
1.58.0Fixed in
What to do now
Update Forminator Forms – Contact Form, Payment Form & Custom Form Builder to 1.58.0 or later.
Affected versions
- Everything up to and including 1.57.3
Affected: Forminator Forms – Contact Form, Payment Form & Custom Form Builder (plugin, forminator)
What the vulnerability is
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.57.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.