CRITICAL 9.1 CVE-2026-92229 Published 19 Sept 2026

Forminator WordPress Plugin Arbitrary Shortcode Execution Vulnerability

Worried this affects your website?

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2.

This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.

  • Affected versions: all versions up to and including 1.57.2
  • Attackers: unauthenticated
  • Impact: arbitrary shortcode execution

Reference: CVE-2026-92229 on NVD

← Back to Security News