Vulnerabilities / Forminator Forms / WPSEC-2026-0624
Forminator Forms <= 1.57.3.1 - Unauthenticated Insecure Direct Object Reference via Stripe PaymentIntent ID
Medium 6.5
CWE-639Fixed in 1.58.0
- ID
- WPSEC-2026-0624
- Plugin
- Forminator Forms – Contact Form, Payment Form & Custom Form Builder (forminator)
- Affected
- all versions before 1.58.0
- Remediation
- Update to 1.58.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Weakness
- CWE-639
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
- Attack surface
- Forminator Forms on WPSec AttackSurface
- Fix released
- Published
Description
The Forminator Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in its Stripe payment field in all versions up to, and including, 1.57.3.1 due to client-supplied PaymentIntent IDs not being tied to the current form or browser, and a site-wide shared PaymentIntent cache. This makes it possible for unauthenticated attackers to reuse or modify PaymentIntents belonging to other visitors or forms and obtain their client secrets.
References
- https://wpsec.com/vuln/WPSEC-2026-0624/
- https://plugins.svn.wordpress.org/forminator/tags/1.58.0/
- https://wordpress.org/plugins/forminator/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS