Authorization Bypass Vulnerability in Forminator Plugin by WordPress
CVE-2026-2729

5.3MEDIUM

What is CVE-2026-2729?

The Forminator plugin for WordPress suffers from an authorization bypass vulnerability affecting all versions up to 1.52.0. This occurs due to inadequate user verification when processing Stripe PaymentIntent identifiers supplied by an attacker in the public payment flow. As a result, unauthenticated attackers can exploit this flaw to complete high-value paid forms by reusing previously succeeded low-value Stripe PaymentIntents, leading to conditions of underpayment and payment bypass.

Affected Version(s)

Forminator Forms – Contact Form, Payment Form & Custom Form Builder 0 <= 1.52.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kittipat Jitphonchana
.