Skip to main content
EPSS 0.2%top 92%

CVE-2026-87074: CWE-862 Missing Authorization in Forminator Forms

0
Low
VulnerabilityCVE-2026-87074cvecve-2026-87074cwe-862
Published: 09/23/2026 (09/23/2026, 06:00:20 UTC)
Source: CVE Database V5
Product: Forminator Forms

Description

The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail configuration to any address, carrying a link of their choosing inside the site's own template. The token that authorises the send is handed to the anonymous caller by the Forminator Forms WordPress plugin before 1.57.2.1 itself and can be replayed without limit.

CVSS v3.1

Score 3.7low

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected software

Forminator Forms

Affected versions
>=1.17.1 <1.57.2.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 06:18:39 UTC

Technical Analysis

The Forminator Forms WordPress plugin before version 1.57.2.1 suffers from a missing authorization vulnerability (CWE-862) in its saved-draft notification feature. The plugin fails to associate the notification with the visitor who created the draft and accepts both the recipient email address and the embedded link from the request parameters. Consequently, unauthenticated attackers can cause the site to send emails to arbitrary recipients containing attacker-chosen links. The authorization token required to send these messages is issued by the plugin itself to anonymous users and can be replayed without limitation, enabling repeated abuse.

Potential Impact

Unauthenticated attackers can abuse the site’s mail configuration to send emails to arbitrary recipients with attacker-controlled content, potentially facilitating phishing or spam campaigns that appear to originate from the vulnerable site. The unlimited replay of the authorization token increases the risk and scale of abuse. This could damage the site's reputation and trustworthiness.

Mitigation Recommendations

A fix is available in Forminator Forms version 1.57.2.1. Users should upgrade to this version or later to remediate the vulnerability. Until patched, restrict access to the affected functionality or implement additional access controls if possible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
WPScan
Date Reserved
2026-09-08T19:05:47.054Z
State
PUBLISHED

Threat ID: 6ab36d43f7a7c541065abcc5

Added to database: 09/23/2026, 06:10:11 UTC

Last enriched: 09/23/2026, 06:18:39 UTC

Last updated: 09/24/2026, 02:48:41 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses