Missing Authorization Flaw in WPMU DEV Forminator Plugin
CVE-2026-96335

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 October 2026

What is CVE-2026-96335?

A vulnerability exists in WPMU DEV's Forminator plugin that allows threat actors to exploit misconfigured access control security levels. This leads to unauthorized access to sensitive features and data, compromising the integrity and security of the application. Users running versions from n/a through 1.57.2 are particularly at risk, as proper authorization checks are not enforced, making it easier for malicious users to manipulate functionalities that should be restricted. It is crucial for users to update their plugin installations to mitigate potential threats associated with this vulnerability.

Affected Version(s)

Forminator <= 1.57.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal | Patchstack
.