PatchSiren

Forminator CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Forminator CVE published 2026-09-20

CVE-2026-87067

The Forminator Forms WordPress plugin before 1.57.2.1 has a deserialization vulnerability allowing users with forms-management permission to write files and execute code. This permission can be granted to roles below administrator level, making the issue reachable by lower-privileged users on affected sites. The vulnerability can lead to potential code execution and unauthorized file writing, emphasizing [truncated]