Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3807 articles · 205527 vulns · 37/41 feeds (7d)
← Back to list
5.3
CVE-2026-12998
wpmudev · forminator forms – contact form, payment form & custom form builder

Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter

Description

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the 'draft' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate sequential integer entry IDs via the 'draft' parameter and read other users' saved draft form data, including names, email addresses, phone numbers, addresses, and free-form message content. This is only exploitable on forms that have the 'Save and Continue' feature enabled.

Affected Products

VendorProductVersions
wpmudevforminator forms – contact form, payment form & custom form builder0

References

  • https://www.wordfence.com/threat-intel/vulnerabilities/id/36aa7193-0e31-4084-97d0-8c22ebff3f05?source=cve
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.0/library/render/class-render-form.php#L2011
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.0/library/render/class-render-form.php#L2000
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.0/library/model/class-form-entry-model.php#L160
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.0/library/model/class-form-entry-model.php#L212
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.52.2/library/render/class-render-form.php#L2011
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.52.2/library/render/class-render-form.php#L2000
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.52.2/library/model/class-form-entry-model.php#L160
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.52.2/library/model/class-form-entry-model.php#L212
  • https://plugins.trac.wordpress.org/changeset?reponame=&old=3593819%40forminator&new=3593819%40forminator

Related News (1 articles)

Tier C
VulDB12d ago
CVE-2026-12998 | wpmudev Forminator Forms Plugin up to 1.55.0.2 on WordPress draft authorization
→ No new info (linked only)
CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-639
PublishedAug 16, 2026
Trending Score7
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-76581EXPKEV
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
Trending: 96
HIGHCVE-2026-18324
Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
Trending: 26
HIGHCVE-2026-18328
Forminator Forms <= 1.57.0 - Unauthenticated DOM-Based Cross-Site Scripting via 'error_description' Parameter
Trending: 24
CRITICALCVE-2026-15748
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
Trending: 19
HIGHCVE-2026-18323
Forminator Forms <= 1.57.0.2 - Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft)
Trending: 17

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 16, 2026
Discovered by ZDM
Aug 16, 2026