Form Submission Metadata Injection in Forminator Forms Plugin by WPForm
CVE-2026-87071
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 23 September 2026
Badges
What is CVE-2026-87071?
The Forminator Forms plugin for WordPress prior to version 1.57.2.1 is susceptible to a vulnerability that allows unauthenticated users to submit arbitrary metadata while filling out public forms. This flaw allows attackers to attach unauthorized metadata keys to form submissions, including those reserved by WordPress itself, potentially leading to information leakage or data manipulation. This vulnerability poses a significant risk to WordPress installations utilizing the affected plugin, as it can compromise the integrity of the post content created through form submissions.
Affected Version(s)
Forminator Forms 0 < 1.57.2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved