Vulnerabilities / Forminator Forms / WPSEC-2026-0618

Forminator Forms <= 1.57.3 - Unauthenticated Arbitrary Shortcode Execution via User-Agent Header and Referer URL

Medium 5.6 CWE-94Fixed in 1.57.3.1
ID
WPSEC-2026-0618
Plugin
Forminator Forms – Contact Form, Payment Form & Custom Form Builder (forminator)
Affected
all versions before 1.57.3.1
Remediation
Update to 1.57.3.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness
CWE-94
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
Attack surface
Forminator Forms on WPSec AttackSurface
Fix released
Published

Description

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 1.57.3. When a quiz notification email contained the {quiz_result} tag, the plugin replaced request-controlled tags such as {user_agent}, {refer_url} and {http_refer} and then ran do_shortcode() on the whole message without removing shortcode syntax from those values. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when completing a quiz whose notification uses these tags.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0