CVE-2026-87074: CWE-862 Missing Authorization in Forminator Forms
The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail configuration to any address, carrying a link of their choosing inside the site's own template. The token that authorises the send is handed to the anonymous caller by the Forminator Forms WordPress plugin before 1.57.2.1 itself and can be replayed without limit.
AI Analysis
Technical Summary
The Forminator Forms WordPress plugin before version 1.57.2.1 suffers from a missing authorization vulnerability (CWE-862) in its saved-draft notification feature. The plugin fails to associate the notification with the visitor who created the draft and accepts both the recipient email address and the embedded link from the request parameters. Consequently, unauthenticated attackers can cause the site to send emails to arbitrary recipients containing attacker-chosen links. The authorization token required to send these messages is issued by the plugin itself to anonymous users and can be replayed without limitation, enabling repeated abuse.
Potential Impact
Unauthenticated attackers can abuse the site’s mail configuration to send emails to arbitrary recipients with attacker-controlled content, potentially facilitating phishing or spam campaigns that appear to originate from the vulnerable site. The unlimited replay of the authorization token increases the risk and scale of abuse. This could damage the site's reputation and trustworthiness.
Mitigation Recommendations
A fix is available in Forminator Forms version 1.57.2.1. Users should upgrade to this version or later to remediate the vulnerability. Until patched, restrict access to the affected functionality or implement additional access controls if possible.
CVE-2026-87074: CWE-862 Missing Authorization in Forminator Forms
Description
The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail configuration to any address, carrying a link of their choosing inside the site's own template. The token that authorises the send is handed to the anonymous caller by the Forminator Forms WordPress plugin before 1.57.2.1 itself and can be replayed without limit.
CVSS v3.1
Score 3.7low
Affected software
Forminator Forms
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Forminator Forms WordPress plugin before version 1.57.2.1 suffers from a missing authorization vulnerability (CWE-862) in its saved-draft notification feature. The plugin fails to associate the notification with the visitor who created the draft and accepts both the recipient email address and the embedded link from the request parameters. Consequently, unauthenticated attackers can cause the site to send emails to arbitrary recipients containing attacker-chosen links. The authorization token required to send these messages is issued by the plugin itself to anonymous users and can be replayed without limitation, enabling repeated abuse.
Potential Impact
Unauthenticated attackers can abuse the site’s mail configuration to send emails to arbitrary recipients with attacker-controlled content, potentially facilitating phishing or spam campaigns that appear to originate from the vulnerable site. The unlimited replay of the authorization token increases the risk and scale of abuse. This could damage the site's reputation and trustworthiness.
Mitigation Recommendations
A fix is available in Forminator Forms version 1.57.2.1. Users should upgrade to this version or later to remediate the vulnerability. Until patched, restrict access to the affected functionality or implement additional access controls if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-08T19:05:47.054Z
- State
- PUBLISHED
Threat ID: 6ab36d43f7a7c541065abcc5
Added to database: 09/23/2026, 06:10:11 UTC
Last enriched: 09/23/2026, 06:18:39 UTC
Last updated: 09/24/2026, 02:48:41 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.