Path Traversal Vulnerability in Forminator Forms Plugin for WordPress
CVE-2026-5192
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 May 2026
What is CVE-2026-5192?
The Forminator Forms plugin for WordPress allows unauthenticated attackers to exploit a path traversal vulnerability through the 'upload-1[file][file_path]' parameter. This issue, present in versions up to 1.52.1, enables attackers to read arbitrary files on the server, potentially exposing sensitive information. Successful exploitation necessitates a public form with a File Upload field where both 'Save and Continue' and email notifications for file attachments are enabled, ultimately compromising site security.
Affected Version(s)
Forminator Forms β Contact Form, Payment Form & Custom Form Builder 0 <= 1.52.1