Vulnerabilities / Forminator Forms / WPSEC-2026-0618
Forminator Forms <= 1.57.3 - Unauthenticated Arbitrary Shortcode Execution via User-Agent Header and Referer URL
Medium 5.6
CWE-94Fixed in 1.57.3.1
- ID
- WPSEC-2026-0618
- Plugin
- Forminator Forms – Contact Form, Payment Form & Custom Form Builder (forminator)
- Affected
- all versions before 1.57.3.1
- Remediation
- Update to 1.57.3.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
- Weakness
- CWE-94
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
- Attack surface
- Forminator Forms on WPSec AttackSurface
- Fix released
- Published
Description
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 1.57.3. When a quiz notification email contained the {quiz_result} tag, the plugin replaced request-controlled tags such as {user_agent}, {refer_url} and {http_refer} and then ran do_shortcode() on the whole message without removing shortcode syntax from those values. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when completing a quiz whose notification uses these tags.
References
- https://wpsec.com/vuln/WPSEC-2026-0618/
- https://plugins.svn.wordpress.org/forminator/tags/1.57.3.1/
- https://wordpress.org/plugins/forminator/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS