---
id: CVE-2026-92229
title: >-
  The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder
  plugin for WordPress is vulnerable to arbitrary shortcode execution in all
  versions up to, and including, 1.57.2
summary: >-
  The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder
  plugin for WordPress is vulnerable to arbitrary shortcode execution in all
  versions up to, and including, 1.57.2. This is due to the software allowing
  users to e…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-94
vendor: wpmudev
product: 'Forminator Forms – Contact Form, Payment Form & Custom Form Builder'
affected:
  - forminator_forms_contact_form_payment_form_custom_form_builder <= 1.57.2
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:33:33.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92229'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/abstracts/abstract-class-front-action.php#L127
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/modules/quizzes/front/front-action.php#L60
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/modules/quizzes/front/front-action.php#L837
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/modules/quizzes/front/front-action.php#L870
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3700724%40forminator&new=3700724%40forminator
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/7c28869c-c880-4322-9f17-09495a08576e?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
  - cve.org
epss: 0.00727
epssPercentile: 0.52126
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/murrez/CVE-2026-92229'
  checkedAt: '2026-09-25T08:21:23.762Z'
exploitAvailable: true
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-19T13:22:43.054347Z'
ingestedAt: '2026-09-19T02:56:32.978Z'
---

## Overview

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
