CVE · High

CVE-2026-28111 — Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.56.0.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-28111 Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.56.0.1 Incorrect Privilege Assignment High 8.8 < 1.56.0.1 1.56.0.1 2026-08-03

CVE-2026-28111

A vulnerability exists in certain versions of the Forminator plugin, where an attacker can exploit a flaw to elevate their privileges from contributor level and gain unauthorized access to sensitive areas of a WordPress site. This issue affects Forminator plugin versions up to 1.56.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.