Vulnerabilities / Forminator Forms / WPSEC-2026-0622

Forminator Forms <= 1.57.3.1 - Unauthenticated CAPTCHA Bypass on Payment Forms

Medium 5.3 CWE-862Fixed in 1.58.0
ID
WPSEC-2026-0622
Plugin
Forminator Forms – Contact Form, Payment Form & Custom Form Builder (forminator)
Affected
all versions before 1.58.0
Remediation
Update to 1.58.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-862
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
Attack surface
Forminator Forms on WPSec AttackSurface
Fix released
Published

Description

The Forminator Forms plugin for WordPress is vulnerable to a CAPTCHA bypass in all versions up to, and including, 1.57.3.1. Submissions to any form containing a Stripe or PayPal field skipped CAPTCHA validation entirely. This makes it possible for unauthenticated attackers to submit such forms without solving the CAPTCHA the site owner configured, defeating its spam and abuse protection.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0