CVE-2026-32409
WordPress Forminator plugin <= 1.50.2 - Broken Access Control vulnerability
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
11th
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Forminator: from n/a through <= 1.50.2.
| CWE | CWE-862 |
| Vendor | wpmu dev - your all-in-one wordpress platform |
| Product | forminator |
| Published | Mar 13, 2026 |
| Last Updated | Apr 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for wpmu dev - your all-in-one wordpress platform forminator
Be the first to know when new medium vulnerabilities affecting wpmu dev - your all-in-one wordpress platform forminator are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WPMU DEV - Your All-in-One WordPress Platform / Forminator
0 โค 1.50.2
References
Credits
Nguyen Tien Dung | Patchstack Bug Bounty Program