Vulnerabilities / Forminator Forms / WPSEC-2026-0624

Forminator Forms <= 1.57.3.1 - Unauthenticated Insecure Direct Object Reference via Stripe PaymentIntent ID

Medium 6.5 CWE-639Fixed in 1.58.0
ID
WPSEC-2026-0624
Plugin
Forminator Forms – Contact Form, Payment Form & Custom Form Builder (forminator)
Affected
all versions before 1.58.0
Remediation
Update to 1.58.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-639
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
Attack surface
Forminator Forms on WPSec AttackSurface
Fix released
Published

Description

The Forminator Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in its Stripe payment field in all versions up to, and including, 1.57.3.1 due to client-supplied PaymentIntent IDs not being tied to the current form or browser, and a site-wide shared PaymentIntent cache. This makes it possible for unauthenticated attackers to reuse or modify PaymentIntents belonging to other visitors or forms and obtain their client secrets.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0