PatchSiren cyber security CVE debrief
CVE-2026-87067 Forminator CVE debrief
The Forminator Forms WordPress plugin before 1.57.2.1 has a deserialization vulnerability allowing users with forms-management permission to write files and execute code. This permission can be granted to roles below administrator level, making the issue reachable by lower-privileged users on affected sites. The vulnerability can lead to potential code execution and unauthorized file writing, emphasizing the need for site administrators and defenders to assess exposure and prioritize patching or mitigation.
- Vendor
- Forminator
- Product
- Forms WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-20
- Original CVE updated
- 2026-09-20
- Advisory published
- 2026-09-20
- Advisory updated
- 2026-09-20
Who should care
Site administrators and defenders responsible for WordPress installations using the Forminator Forms plugin, especially those who have granted forms-management permissions to lower-privileged roles, should assess exposure and prioritize patching or mitigation.
Why it matters
CVE-2026-87067 is a deserialization vulnerability in the Forminator Forms WordPress plugin that allows users with forms-management permissions to execute arbitrary code and write files. This issue is significant because it can be exploited by lower-privileged users on sites that have granted such permissions, potentially leading to code execution and unauthorized file writing. Defenders should prioritize patching or mitigating this vulnerability, especially on sites with complex role structures or lower-privileged users with forms-management permissions. The impact is currently limited by the lack of reported exploitation and specific victim information, but verification of affected versions and remediation status is necessary.
- Potential code execution on affected sites
- Unauthorized file writing on affected sites
- Elevation of privileges for users with forms-management permissions
- Need for verification of affected versions and remediation status
Technical summary
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict class instantiation during deserialization of XML-RPC request values, allowing users with forms-management permission to write files and execute arbitrary code. This issue arises from the plugin's insecure handling of XML-RPC requests, which can be exploited by lower-privileged users who have been granted forms-management permissions. The vulnerability's impact includes potential code execution and unauthorized file writing on affected sites, emphasizing the need for defenders to prioritize patching or mitigating this vulnerability.
Defensive priority
Defenders should prioritize patching or mitigating this vulnerability, especially on sites with lower-privileged users who have forms-management permissions.
Recommended defensive actions
- Patch the Forminator Forms WordPress plugin to version 1.57.2.1 or later
- Review and limit forms-management permissions to only necessary roles
- Monitor for suspicious activity related to the Forminator Forms plugin
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability is described in the CVE and NVD records, with additional details from a WPScan source reference. However, specific exploitation details or victim information are not provided. The lack of reported exploitation and specific victim information currently limits the impact, but verification of affected versions and remediation status is necessary. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87067 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87067
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87067 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87067
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/9f5da02e-55af-463f-8b1a-9fe792d589c4/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.