Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-66583: Forminator plugin lets attackers execute code on site

CVE-2026-66583 · published 1 month ago
Summary

The Forminator add‑on for WordPress, in versions up through 1.57.0, can be fooled by anyone on the internet to insert harmful data that makes the website run unwanted code. This could let a hacker take control of the site or steal information. Update the plugin to the newest release, or remove it, to close the risk.

What to do
  • Update wpmu dev forminator to version 1.57.1.
Affected software
VendorProductAffected versions
wpmu dev forminator <= 1.57.0
Fix: upgrade to 1.57.1
Original advisory text
WordPress Forminator plugin <= 1.57.0 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published20 Aug 2026
Updated27 Sep 2026
First seen20 Aug 2026
Sources
CVE-2026-66583 · MITRE
Track software like this
Free during beta