---
id: CVE-2026-87074
title: >-
  The Forminator Forms  WordPress plugin before 1.57.2.1 does not bind its
  saved-draft notification to the visitor who created the draft, and takes both
  the recipient address and the link written into the message from the request,
  so unaut…
summary: >-
  The Forminator Forms  WordPress plugin before 1.57.2.1 does not bind its
  saved-draft notification to the visitor who created the draft, and takes both
  the recipient address and the link written into the message from the request,
  so unaut…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
product: Forminator Forms
affected:
  - forminator_forms >= 1.17.1 < 1.57.2.1
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:13:31.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87074'
references:
  - url: 'https://wpscan.com/vulnerability/74ca7b28-25b7-4d68-ad4b-4785b1d2c666/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00154
epssPercentile: 0.03792
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T10:39:07.818340Z'
ingestedAt: '2026-09-23T06:17:57.896Z'
---

## Overview

The Forminator Forms  WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail configuration to any address, carrying a link of their choosing inside the site's own template. The token that authorises the send is handed to the anonymous caller by the Forminator Forms  WordPress plugin before 1.57.2.1 itself and can be replayed without limit.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
