CRITICAL 9.8 CVE-2026-66583 Published 20 Aug 2026

Forminator Plugin PHP Object Injection

Worried this affects one of your servers?

Forminator, a WordPress plugin, is affected by an unauthenticated PHP Object Injection vulnerability in versions up to 1.57.0.

This flaw allows attackers to inject malicious PHP objects, potentially leading to remote code execution.

Reference: CVE-2026-66583 on NVD

← Back to Security News