CVE Database /
CVE-2026-12998
CVE · Medium
CVE-2026-12998 — Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.55.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12998
|
Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.55.1 |
Authorization Bypass Through User-Controlled Key |
Medium
5.3
|
< 1.55.1
|
1.55.1 |
2026-08-15 |
—
|
CVE-2026-12998
The Forminator Forms plugin for WordPress has a vulnerability that allows attackers to access and read draft form data from other users. This occurs because the plugin does not properly validate a user-controlled parameter, allowing attackers to enumerate and access specific draft IDs. As a result, attackers can obtain sensitive information such as names, email addresses, phone numbers, and message content from other users' draft forms, provided the 'Save and Continue' feature is enabled.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings