๐Ÿ” CVE Alert

CVE-2026-87074

UNKNOWN 0.0

Forminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sending with Attacker-Controlled Link

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail configuration to any address, carrying a link of their choosing inside the site's own template. The token that authorises the send is handed to the anonymous caller by the Forminator Forms WordPress plugin before 1.57.2.1 itself and can be replayed without limit.

Vendor unknown
Product forminator forms
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for unknown forminator forms

Be the first to know when new unknown vulnerabilities affecting unknown forminator forms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Forminator Forms
1.17.1 < 1.57.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/74ca7b28-25b7-4d68-ad4b-4785b1d2c666/

Credits

vuxvinh WPScan