CVE-2026-87071
Received Received - Intake

Forminator Plugin Metadata Injection Vulnerability

Vulnerability report for CVE-2026-87071, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthenticated visitors submitting a public form that collects post content can attach metadata of their choosing to the post their submission creates.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpforms forminator_forms to 1.57.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Forminator Forms WordPress plugin before version 1.57.2.1 has a flaw where it does not restrict metadata keys submitted via public forms. This allows unauthenticated users to inject arbitrary metadata, including WordPress reserved keys, into posts created by their form submissions.

Detection Guidance

Check the installed version of the Forminator Forms plugin in WordPress. If it is below 1.57.2.1, the system is vulnerable. Use commands like 'wp plugin list' in WP-CLI or inspect the plugin files in the WordPress plugins directory for version information.

Impact Analysis

An attacker could manipulate post metadata to alter post behavior or inject malicious data. This could lead to unintended post modifications, potential data corruption, or enabling further attacks if WordPress internal keys are overwritten.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized metadata injection into posts. If exploited, it may lead to improper handling of personal or sensitive data stored in metadata, violating data integrity and confidentiality requirements under these regulations.

Mitigation Strategies

Update the Forminator Forms plugin to version 1.57.2.1 or later immediately. Disable public forms if not required until the update is applied. Monitor for unauthorized post metadata changes as a sign of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87071. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart