Insecure Direct Object Reference in Forminator Plugin for WordPress
CVE-2026-12998

5.3MEDIUM

What is CVE-2026-12998?

The Forminator Forms plugin for WordPress is susceptible to an Insecure Direct Object Reference due to inadequate validation of user-controlled keys, specifically in the 'draft' parameter. This vulnerability allows unauthenticated users to exploit forms with the 'Save and Continue' feature enabled, leading them to enumerate sequential integer entry IDs. Consequently, attackers can access and read saved draft form data from other users, including sensitive information such as names, email addresses, phone numbers, and text messages.

Affected Version(s)

Forminator Forms – Contact Form, Payment Form & Custom Form Builder 0 <= 1.55.0.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

se1en
.