PHP Object Injection Vulnerability in Forminator Plugin by WordPress
CVE-2026-66583
9.8CRITICAL
What is CVE-2026-66583?
A security vulnerability has been identified in the Forminator plugin versions up to 1.57.0, allowing unauthenticated PHP Object Injection. This flaw can potentially be exploited by malicious actors to execute arbitrary code, posing a significant risk to websites employing this plugin. Website administrators are strongly advised to upgrade to a patched version to mitigate potential threats associated with this vulnerability.
Affected Version(s)
Forminator <= 1.57.0