CVE-2026-87067
Received Received - Intake

Arbitrary Code Execution in Forminator WordPress Plugin

Vulnerability report for CVE-2026-87067, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-20

Last updated on: 2026-09-20

Assigner: WPScan

Description

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Forminator Forms WordPress plugin before 1.57.2.1's own settings, so the issue is reachable well below administrator on sites that use that feature.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-20
Last Modified
2026-09-20
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wpforms forminator 1.57.2.1
wpforms forminator_forms to 1.57.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Forminator Forms WordPress plugin before version 1.57.2.1. It involves an XML-RPC PHP object injection flaw that allows authenticated users with forms-management permission to write arbitrary files and execute remote code. By default, only administrators have this permission, but site admins can grant it to other roles.

Detection Guidance

Check if your WordPress site uses the Forminator Forms plugin version prior to 1.57.2.1. Inspect XML-RPC requests for unusual file writes or code execution patterns. Use WordPress admin tools to review user permissions for forms-management access.

Impact Analysis

An attacker with forms-management permission could exploit this to write malicious files and execute arbitrary code on your WordPress site. This could lead to full site compromise, data theft, or further attacks. The impact depends on the attacker's goals and the site's configuration.

Compliance Impact

This vulnerability could lead to unauthorized access, data breaches, or code execution, which may violate GDPR, HIPAA, or other regulations. Compliance risks include data exposure, lack of access controls, and failure to protect sensitive information.

Mitigation Strategies

Update the Forminator Forms plugin to version 1.57.2.1 or later immediately. Review and restrict forms-management permissions to trusted users only. Monitor for unauthorized file writes or code execution attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87067. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart