CVE Database /
CVE-2026-32409
CVE · Medium
CVE-2026-32409 — Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.50.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-32409
|
Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.50.3 |
Missing Authorization |
Medium
5.3
|
< 1.50.3
|
1.50.3 |
2026-02-22 |
—
|
CVE-2026-32409
A security flaw exists within the Forminator plugin for WordPress, where insufficient permission checks allow malicious individuals to execute an unauthorized operation without requiring authentication, affecting versions of the plugin up to 1.50.2. The vulnerability stems from a missing capability verification on a specific function. This oversight enables unauthenticated attackers to bypass normal access controls and perform actions they shouldn't be able to do.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings