CVE-2026-87070
Received Received - Intake

Forminator Poll Voting Limit Bypass via Proxy Header

Vulnerability report for CVE-2026-87070, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwarding headers over the connecting address, and it uses that value both to enforce its per-visitor voting limit and to record who submitted an entry. Unauthenticated visitors can therefore vote without limit on any poll and can choose the address stored against every submission they make.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wpforms forminator_forms to 1.57.2.1 (exc)
wpform forminator_forms to 1.57.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-348 The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Forminator Forms WordPress plugin before version 1.57.2.1 has a security flaw where it does not check if a request comes from a trusted proxy before using client-supplied forwarding headers like X-Forwarded-For to determine the visitor's IP address. This allows unauthenticated users to spoof their IP address and bypass voting limits on polls. Attackers can also manipulate the stored submission details by changing their recorded IP address.

Detection Guidance

To detect this vulnerability, check if your Forminator Forms plugin version is below 1.57.2.1. Inspect server logs for unusual voting patterns or multiple submissions from the same IP address in a short time. Monitor for requests containing proxy headers like X-Forwarded-For without proper validation.

Impact Analysis

If you use the Forminator Forms plugin before version 1.57.2.1, attackers can exploit this vulnerability to vote multiple times on your polls without limit. They can also alter the IP addresses associated with form submissions, making it difficult to track or block malicious activity. This could skew poll results and compromise the integrity of your data.

Mitigation Strategies

Immediately update the Forminator Forms plugin to version 1.57.2.1 or later. Configure your web server to validate and restrict proxy headers to trusted sources. Review and remove any unauthorized poll submissions or votes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87070. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart