CVE · Medium

CVE-2026-12998 — Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.55.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12998 Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.55.1 Authorization Bypass Through User-Controlled Key Medium 5.3 < 1.55.1 1.55.1 2026-08-15

CVE-2026-12998

The Forminator Forms plugin for WordPress has a vulnerability that allows attackers to access and read draft form data from other users. This occurs because the plugin does not properly validate a user-controlled parameter, allowing attackers to enumerate and access specific draft IDs. As a result, attackers can obtain sensitive information such as names, email addresses, phone numbers, and message content from other users' draft forms, provided the 'Save and Continue' feature is enabled.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.