Arbitrary Shortcode Execution Vulnerability in Forminator Plugin for WordPress
CVE-2026-92229
9.1CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 September 2026
What is CVE-2026-92229?
The Forminator Forms plugin for WordPress enables arbitrary shortcode execution when users can trigger actions without proper validation. This vulnerability affects all versions up to 1.57.2 and allows unauthenticated attackers to exploit the do_shortcode function, posing a significant risk to website security. Site owners using this plugin should apply necessary patches or updates to mitigate potential exploits.
Affected Version(s)
Forminator Forms β Contact Form, Payment Form & Custom Form Builder 0 <= 1.57.2