CVE-2026-82220 MEDIUM

CVE-2026-82220: WordPress Forminator plugin <= 1.57.1 - Other vulnerability Type vulnerability

Vendor Wpmu Dev
Product Forminator
Weakness CWE-294
Published August 28, 2026
Last update August 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.

Explanation of Vulnerability in Simple Terms

02Summary

Forminator versions up to 1.57.1 contain an authentication bypass vulnerability that allows attackers to replay captured authentication tokens to gain unauthorized access. The vulnerability requires network access but no user interaction or elevated privileges. An attacker can intercept and reuse valid authentication credentials to perform unauthorized actions on the site.

What an attacker can do

03Attacker Capabilities

Replay captured authentication tokens to bypass login and perform unauthorized actions on the site.

Potential impact on your site

04Site Impact

Unauthorized users can gain access to Forminator functionality and potentially modify forms or access submitted data without valid credentials.

Conditions required to exploit

05Prerequisites

Attacker must be able to capture valid authentication tokens (e.g., via network sniffing or man-in-the-middle attack).

Key dates

06Disclosure timeline

August 28, 2026 CVE published