PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87067 Forminator CVE debrief

The Forminator Forms WordPress plugin before 1.57.2.1 has a deserialization vulnerability allowing users with forms-management permission to write files and execute code. This permission can be granted to roles below administrator level, making the issue reachable by lower-privileged users on affected sites. The vulnerability can lead to potential code execution and unauthorized file writing, emphasizing the need for site administrators and defenders to assess exposure and prioritize patching or mitigation.

Vendor
Forminator
Product
Forms WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-20
Original CVE updated
2026-09-20
Advisory published
2026-09-20
Advisory updated
2026-09-20

Who should care

Site administrators and defenders responsible for WordPress installations using the Forminator Forms plugin, especially those who have granted forms-management permissions to lower-privileged roles, should assess exposure and prioritize patching or mitigation.

Why it matters

CVE-2026-87067 is a deserialization vulnerability in the Forminator Forms WordPress plugin that allows users with forms-management permissions to execute arbitrary code and write files. This issue is significant because it can be exploited by lower-privileged users on sites that have granted such permissions, potentially leading to code execution and unauthorized file writing. Defenders should prioritize patching or mitigating this vulnerability, especially on sites with complex role structures or lower-privileged users with forms-management permissions. The impact is currently limited by the lack of reported exploitation and specific victim information, but verification of affected versions and remediation status is necessary.

  • Potential code execution on affected sites
  • Unauthorized file writing on affected sites
  • Elevation of privileges for users with forms-management permissions
  • Need for verification of affected versions and remediation status

Technical summary

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict class instantiation during deserialization of XML-RPC request values, allowing users with forms-management permission to write files and execute arbitrary code. This issue arises from the plugin's insecure handling of XML-RPC requests, which can be exploited by lower-privileged users who have been granted forms-management permissions. The vulnerability's impact includes potential code execution and unauthorized file writing on affected sites, emphasizing the need for defenders to prioritize patching or mitigating this vulnerability.

Defensive priority

Defenders should prioritize patching or mitigating this vulnerability, especially on sites with lower-privileged users who have forms-management permissions.

Recommended defensive actions

  • Patch the Forminator Forms WordPress plugin to version 1.57.2.1 or later
  • Review and limit forms-management permissions to only necessary roles
  • Monitor for suspicious activity related to the Forminator Forms plugin
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability is described in the CVE and NVD records, with additional details from a WPScan source reference. However, specific exploitation details or victim information are not provided. The lack of reported exploitation and specific victim information currently limits the impact, but verification of affected versions and remediation status is necessary. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87067 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87067

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87067 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87067

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.