CRITICAL
9.1 CVE-2026-92229 Published 19 Sept 2026
Forminator WordPress Plugin Arbitrary Shortcode Execution Vulnerability
Worried this affects your website?
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2.
This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.
- Affected versions: all versions up to and including 1.57.2
- Attackers: unauthenticated
- Impact: arbitrary shortcode execution
Reference: CVE-2026-92229 on NVD
← Back to Security News