CVE-2026-2729
Deferred Deferred - Pending Action
Authorization Bypass in Forminator WordPress Plugin

Publication date: 2026-05-05

Last updated on: 2026-05-05

Assigner: Wordfence

Description
The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. This is due to the plugin not properly verifying that a user is authorized to perform an action when processing attacker-supplied Stripe PaymentIntent identifiers in the public payment flow. This makes it possible for unauthenticated attackers to submit high-value paid forms as completed by reusing a previously succeeded low-value Stripe PaymentIntent, resulting in underpayment/payment bypass conditions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-05
Last Modified
2026-05-05
Generated
2026-05-07
AI Q&A
2026-05-05
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
wpform forminator to 1.52.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

The Forminator plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 1.52.0. This occurs because the plugin does not properly verify whether a user is authorized to perform certain actions when processing Stripe PaymentIntent identifiers supplied by an attacker in the public payment flow.

As a result, unauthenticated attackers can reuse previously succeeded low-value Stripe PaymentIntent identifiers to submit high-value paid forms as completed, effectively bypassing payment requirements.


How can this vulnerability impact me? :

This vulnerability can allow attackers to bypass payment by submitting high-value forms as completed without actually paying the required amount. This can lead to financial loss for the website owner or business using the Forminator plugin.

Since the vulnerability allows unauthorized submission of paid forms, it undermines the integrity of payment processing and could result in underpayment or loss of revenue.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart