Skip to main content
Vulnerability Database/CVE-2026-92229

CVE-2026-92229: Forminator WordPress Plugin RCE Vulnerability

CVE-2026-92229 is a remote code execution flaw in Forminator Forms WordPress plugin allowing unauthenticated attackers to execute arbitrary shortcodes. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-92229 Overview

CVE-2026-92229 is a critical arbitrary shortcode execution vulnerability in the Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress. The vulnerability affects all versions up to and including 1.57.2. The plugin fails to validate a user-supplied value before passing it to WordPress's do_shortcode function. Unauthenticated attackers can trigger arbitrary shortcode execution by sending crafted requests to the quiz front-action endpoint. This flaw is classified as improper control of code generation [CWE-94].

Critical Impact

Unauthenticated remote attackers can execute arbitrary WordPress shortcodes, enabling data disclosure, content manipulation, and potential chained exploitation through other installed plugins that register privileged shortcodes.

Affected Products

  • WordPress Forminator Forms plugin versions ≤ 1.57.2
  • Contact Form, Payment Form and Custom Form Builder functionality provided by the plugin
  • WordPress sites processing quiz submissions through Forminator

Discovery Timeline

  • 2026-09-19 - CVE-2026-92229 published to the National Vulnerability Database
  • 2026-09-21 - Last updated in NVD database

Technical Details for CVE-2026-92229

Vulnerability Analysis

The vulnerability resides in Forminator's front-action handling logic for quiz modules. The plugin exposes an unauthenticated action path that reaches do_shortcode with attacker-controlled input. Because WordPress shortcodes execute PHP callbacks registered by core, themes, and plugins, unrestricted invocation of do_shortcode becomes a code-execution primitive against whatever shortcodes are registered on the site.

An attacker can invoke shortcodes that read post content, expose internal data, or trigger side effects such as sending email, creating records, or executing plugin-defined logic. When paired with other vulnerable plugins that register dangerous shortcodes, the impact can extend to full server compromise.

Root Cause

The root cause is missing validation of a value that flows into do_shortcode. Forminator's abstract front-action class and the quiz front-action module accept request parameters and reach shortcode expansion without confirming the value corresponds to an expected, sanitized identifier. See the WordPress Forminator Front Action source and the WordPress Forminator Quiz Front Action source for the affected code paths.

Attack Vector

Exploitation occurs over the network with no authentication and no user interaction. An attacker sends an HTTP request to the exposed Forminator quiz action endpoint with a crafted parameter that embeds a shortcode string. The plugin passes the value into do_shortcode, which parses and executes the shortcode server-side. Refer to the Wordfence Vulnerability Analysis for technical details on the vulnerable request flow.

No verified proof-of-concept code has been published. The vulnerability is described in prose only; see the referenced source lines in the plugin repository for the affected functions.

Detection Methods for CVE-2026-92229

Indicators of Compromise

  • HTTP requests to admin-ajax.php or Forminator quiz action endpoints containing URL-encoded square brackets (%5B, %5D) in parameter values.
  • Unauthenticated POST requests targeting Forminator quiz actions with parameter values matching shortcode syntax such as [shortcode_name ...].
  • Unexpected outbound network activity, new WordPress users, or modified posts following requests to Forminator endpoints.

Detection Strategies

  • Inspect web server access logs for Forminator quiz action requests originating from anonymous sources with shortcode-like payloads.
  • Enable WordPress debug logging and monitor for do_shortcode invocations initiated from front-action handlers.
  • Correlate WordPress plugin version inventories with the vulnerable range (≤ 1.57.2) to identify exposed sites.

Monitoring Recommendations

  • Deploy web application firewall rules that block shortcode syntax in unauthenticated request parameters bound for Forminator endpoints.
  • Track process and file-system telemetry on WordPress hosts for anomalous PHP-initiated writes, cron entries, or outbound connections.
  • Ingest WordPress and web server logs into a central analytics platform to alert on repeated Forminator quiz-action requests from single sources.

How to Mitigate CVE-2026-92229

Immediate Actions Required

  • Update the Forminator Forms plugin to a version above 1.57.2 that includes the fix referenced in the WordPress Forminator Changeset Review.
  • Audit WordPress sites for the presence and version of Forminator, and prioritize public-facing sites for immediate patching.
  • Review recent web server logs for requests matching the exploitation pattern and investigate any suspicious activity.

Patch Information

The vendor addressed the vulnerability in the changeset published for the Forminator plugin repository. Site operators should upgrade to the latest patched release available in the WordPress plugin directory. Review the changeset diff at the WordPress Forminator Changeset Review to confirm the fix is present in a given build.

Workarounds

  • Temporarily deactivate the Forminator plugin on sites that cannot be patched immediately.
  • Restrict access to Forminator front-action endpoints at the web server or WAF layer, blocking requests containing shortcode syntax from unauthenticated sources.
  • Audit and remove or restrict shortcodes registered by other plugins that expose sensitive functionality, reducing the impact of unauthorized do_shortcode invocation.
bash
# Example WAF rule concept: block shortcode syntax in Forminator quiz action parameters
# ModSecurity-style pseudo-rule
SecRule REQUEST_URI "@contains forminator" \
    "chain,deny,status:403,id:1092229,msg:'CVE-2026-92229 shortcode injection attempt'"
    SecRule ARGS "@rx \[[a-zA-Z0-9_\-]+" "t:none,t:urlDecodeUni"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.