WP Clinic
Log in Sign up

CVE · Medium

CVE-2026-2729 — Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.52.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-2729 Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.52.1 Authorization Bypass Through User-Controlled Key Medium 5.3 < 1.52.1 1.52.1 2026-05-04

CVE-2026-2729

The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. This is due to the plugin not properly verifying that a user is authorized to perform an action when processing attacker-supplied Stripe PaymentIntent identifiers in the public payment flow. This makes it possible for unauthenticated attackers to submit high-value paid forms as completed by reusing a previously succeeded low-value Stripe PaymentIntent, resulting in underpayment/payment bypass conditions.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.