CVE-2026-6222
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
Minimum safe version
1.53.0.1
Update to 1.53.0.1 or later to address 49 fixable vulnerabilities
CVE-2026-6214
CVE-2026-2729
CVE-2026-5192
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.50.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
CVE-2026-32409
CVE-2025-14782
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.45.0 - Authenticated (Administrator+) SQL Injection via `order_by` Parameter
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion
Forminator <= 1.44.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via id and data-size Parameters
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.38.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Forminator <= 1.42.0 - Order Replay Vulnerability
Forminator <= 1.42.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'limit'
Forminator <= 1.39.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress Forminator Plugin <= 1.38.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-9700
WordPress Forminator Plugin <= 1.35.1 is vulnerable to Broken Access Control
CVE-2024-9351
CVE-2024-9352
CVE-2024-45625
CVE-2024-7389
CVE-2024-31077
CVE-2024-31857
CVE-2024-28890
CVE-2024-3053
CVE-2024-1794
CVE-2024-29777
CVE-2023-5119
CVE-2023-6133
CVE-2023-4596
CVE-2023-3134
Forminator <= 1.22.1 - Missing Authorization on 'hubspot_support_request' AJAX function
CVE-2021-4417
CVE-2023-2010
CVE-2021-4342
WordPress Forminator Plugin <= 1.22.1 is vulnerable to Broken Access Control
Forminator <= 1.22.1 - Missing Authorization on 'load_recaptcha_preview' AJAX function
Forminator <= 1.22.1 - Missing Authorization on 'load_hcaptcha_preview' AJAX function
WordPress Forminator Plugin <= 1.14.11 is vulnerable to Cross Site Scripting (XSS)
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
Multiple Plugins - CSRF Nonce Bypasses
WordPress Forminator plugin <= 1.5.4 - Authenticated Blind SQL Injection (SQLi) vulnerability
WordPress Forminator plugin <= 1.5.4 - Unauthenticated Persistent Cross-Site Scripting (XSS) vulnerability
WordPress Forminator plugin <= 1.13.4 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress Forminator plugin <= 1.14.8 - Cross-Site Request Forgery (CSRF) vulnerability
CVE-2019-9568
CVE-2019-9567
CVE-2021-24700