Insecure Direct Object Reference in Forminator Plugin for WordPress
CVE-2026-12998
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2026-12998?
The Forminator Forms plugin for WordPress is susceptible to an Insecure Direct Object Reference due to inadequate validation of user-controlled keys, specifically in the 'draft' parameter. This vulnerability allows unauthenticated users to exploit forms with the 'Save and Continue' feature enabled, leading them to enumerate sequential integer entry IDs. Consequently, attackers can access and read saved draft form data from other users, including sensitive information such as names, email addresses, phone numbers, and text messages.
Affected Version(s)
Forminator Forms β Contact Form, Payment Form & Custom Form Builder 0 <= 1.55.0.2