Authorization Bypass Vulnerability in Forminator Plugin by WordPress
CVE-2026-2729
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 May 2026
What is CVE-2026-2729?
The Forminator plugin for WordPress suffers from an authorization bypass vulnerability affecting all versions up to 1.52.0. This occurs due to inadequate user verification when processing Stripe PaymentIntent identifiers supplied by an attacker in the public payment flow. As a result, unauthenticated attackers can exploit this flaw to complete high-value paid forms by reusing previously succeeded low-value Stripe PaymentIntents, leading to conditions of underpayment and payment bypass.
Affected Version(s)
Forminator Forms β Contact Form, Payment Form & Custom Form Builder 0 <= 1.52.0