Vulnerabilities / Forminator Forms / WPSEC-2026-0623

Forminator Forms <= 1.57.3.1 - Unauthenticated PayPal Order Request Tampering via Form Submission

Medium 5.3 CWE-20Fixed in 1.58.0
ID
WPSEC-2026-0623
Plugin
Forminator Forms – Contact Form, Payment Form & Custom Form Builder (forminator)
Affected
all versions before 1.58.0
Remediation
Update to 1.58.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-20
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
Attack surface
Forminator Forms on WPSec AttackSurface
Fix released
Published

Description

The Forminator Forms plugin for WordPress is vulnerable to request tampering in its PayPal order creation handler in all versions up to, and including, 1.57.3.1 due to client-supplied request data being merged into the PayPal create-order request. This makes it possible for unauthenticated attackers to add their own properties to the order sent to PayPal, such as an additional purchase unit, a payee or an application context, on forms that use a PayPal field. The amount recorded for the submission is re-validated against the form settings before the payment is captured.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0