Yet Another WordPress Vulnerability: Forminator Enters the Security Circle

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Challenges in Securing WordPress Sites

At this juncture, safeguarding a WordPress site resembles less a matter of routine maintenance and more an incessant game of Whac-A-Mole, albeit with a keyboard.

Address one plugin vulnerability, only to encounter another. Remedy that issue, and yet another security alert surfaces. Even a plugin previously updated may require urgent revisions due to newly discovered flaws.

A recent case in point is Forminator, a widely utilized WordPress forms plugin crafted by WPMU DEV, boasting over 600,000 installations.

Patchstack has recently revealed a critical vulnerability impacting Forminator versions up to and including 1.57.2, assigning it a CVSS score of 9.1.

This flaw, designated as CVE-2026-92229, permits unauthenticated arbitrary shortcode execution via the current_url parameter. The patched iteration is identified as version 1.57.3.

While this revelation is alarming in itself, it underscores a broader issue: this incident marks merely the latest in a recurring series of security patches associated with the plugin.

At present, Patchstack catalogues a total of 51 patched vulnerabilities in the history of Forminator, encompassing privilege escalation, arbitrary file uploads, PHP object injections, stored cross-site scripting, information disclosures, and security challenges related to multisite functionality.

The official changelog for the WordPress plugin corroborates this troubling trend.

On August 18, Forminator released a series of fixes addressing privilege escalation, PHP object injection, multiple cross-site scripting vulnerabilities, enhancements to Hub Connector security, multisite registration issues, and payment processing security concerns.

Subsequent security enhancements emerged on August 27, followed by another security-centric update, version 1.57.2.1, released on September 17, the same day that version 1.57.3 debuted.

One must ponder how website proprietors are expected to keep pace with such developments.

Maintaining a Cycle of Updates

While WordPress itself is not inherently at fault, a more profound challenge lies within the vast third-party ecosystem surrounding it.

A typical business website may incorporate plugins for forms, SEO, caching, backups, analytics, page construction, security, payment processing, image optimization, and myriad other functions.

Each of these plugins introduces additional lines of code.

Increased code translates to a broader attack surface.

Every supplementary dependency brings along another developer whose security protocols, release timelines, and responsiveness become integral to the website’s overall security framework.

Forminator exemplifies this issue vividly due to its extensive user base.

Patchstack warns that the latest vulnerability necessitates no authentication, and underscores that such flaws are ripe for mass exploitation since attackers can indiscriminately target numerous websites at once, rather than individually selecting victims.

This is a critical point for ordinary website operators to heed.

Cybercriminals are indifferent to whether your site garners 50 visitors monthly or 5 million.

If an automated scanner identifies a vulnerable plugin, your website is reduced to yet another IP address and domain awaiting its turn.

The Burden of Constant Updates

The conventional guidance for WordPress administrators has always been straightforward:

  • Regularly update WordPress.
  • Consistently update your plugins.
  • Continuously update your themes.

This advice remains valid, yet navigating the landscape in 2026 often feels woefully inadequate.

You could dutifully update everything today and still receive a critical vulnerability alert tomorrow.

For instance, Forminator version 1.56.2 addressed an arbitrary file upload vulnerability back in July, only to be followed by another wave of security updates coming in August for the 1.57 branch, culminating in yet another severe alert in September.

This trend does not necessarily indicate carelessness on the part of developers; indeed, actively identifying and remedying vulnerabilities is preferable to leaving them hidden or unresolved.

Nevertheless, for the individual managing the website, this distinction offers scant solace.

The Necessity for Multipronged Security

The era of merely installing WordPress, adding a singular security plugin, and scheduling updates on a monthly basis should likely be regarded as antiquated.

A contemporary WordPress site demands multiple layers of protection.

Automatic vulnerability monitoring should vigilantly observe installed plugins and themes, ensuring swift updates are executed when significant vulnerabilities arise.

A web application firewall adds an essential barrier between the public internet and vulnerable application codes. Unutilized plugins should be entirely removed rather than merely deactivated.

While backups are critical, they serve as the recovery mechanism rather than a proactive security safeguard.

Furthermore, the sheer number of plugins can wield greater significance than many website operators might comprehend.

If two plugins perform nearly identical functions, retaining both provides negligible security advantages. Each added plugin encompasses additional PHP, JavaScript, API endpoints, and database interactions, all requiring eventual security scrutiny.

Timely Updates for Forminator Users

Individuals utilizing Forminator version 1.57.2 or earlier must update to 1.57.3 or later without delay.

Patchstack has classified this issue as broken access control, with a CVSS score of 9.1, indicating that exploitation is possible without authentication.

The official listing on WordPress.org confirms the release of Forminator version 1.57.3 on September 17, alongside version 1.57.2.1, released that same day, which included unspecified security enhancements.

There exists no rational justification for maintaining an affected version online.

The Disconcerting Reality

WordPress’s popularity is attributable, in part, to the flexibility provided by plugins, enabling users to construct almost anything without the need to start from scratch.

A man wearing a tshirt with wordpress logo on it and he is typing on a computer.

This strength, however, simultaneously fuels one of its greatest security challenges.

Each plugin constitutes another variable.

Every added variable bears the potential to falter.

Given the frequency with which vulnerabilities seem to erupt, WordPress administrators must increasingly regard vulnerability monitoring as a continuous operational responsibility, rather than something to address only after receiving a security notification.

Forminator will not be the last plugin to undergo patching this month.

It likely will not even be the final significant plugin to receive an update.

This escalating situation can only be described as absurd.

The current state of WordPress security resembles a relentless game of Whac-A-Mole.

The only distinction is that, should you fail to address one, an unwelcome visitor may infiltrate your website.

Source link: Hackernoon.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading