CVE-2026-92229
RCETitle: Arbitrary Shortcode Execution in Forminator Forms
RCE
Proof Of Concept
PoC Available for CVE-2026-92229
CWE Category
CWE-94
Published Date
Sep 19, 2026
Modified Date
Sep 21, 2026
Exploit Status
Available
Score
9.1
CVSS v3.1
Exploit Probability (EPSS)
0.73%
Vulnerability Summary
CVE-2026-92229: The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Impacted Vendors
Analysis in Progress...
Reference Links
https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/abstracts/abstract-class-front-action.php#L127
https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/modules/quizzes/front/front-action.php#L60
https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/modules/quizzes/front/front-action.php#L837
https://plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/modules/quizzes/front/front-action.php#L870
https://plugins.trac.wordpress.org/changeset?reponame=&old=3700724%40forminator&new=3700724%40forminator
https://www.wordfence.com/threat-intel/vulnerabilities/id/7c28869c-c880-4322-9f17-09495a08576e?source=cve
CVSS v3.1
Source Entity
[email protected]
Severity
CRITICAL
9.1
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2026-92229 Exploits & PoCs (Proof Of Concept)
GitHub
https://github.com/murrez/CVE-2026-92229
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
Attack Vector Matrix
Access Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
CVSS Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Stack
No specific products linked.