• PoC PUBLIC

CVE-2026-92229: pre-auth shortcode execution in wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder

An unauthenticated attacker can execute arbitrary shortcodes on sites running the Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin, enabling remote code paths via WordPress shortcode handling. CVE-2026-92229 affects the 1.x branch, specifically versions 1.57.2 and earlier. Exploitation requires only network access to a site hosting the vulnerable plugin and no valid account or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.00727
CWE
CWE-94
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code exists, so patching or mitigations should be prioritised immediately; treat internet-facing WordPress sites with this plugin as exposed. Apply access restrictions and monitoring now and install the vendor fix as soon as it is released.

What is CVE-2026-92229?

An unauthenticated attacker can execute arbitrary shortcodes on sites running the Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin, enabling remote code paths via WordPress shortcode handling. CVE-2026-92229 affects the 1.x branch, specifically versions 1.57.2 and earlier. Exploitation requires only network access to a site hosting the vulnerable plugin and no valid account or user interaction.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder are affected?

BRANCHAFFECTEDFIXED
1.x1.57.2 and earlier

Is CVE-2026-92229 being exploited?

Public exploit code is available.

How to fix CVE-2026-92229

  1. Remove or deactivate the Forminator Forms plugin on exposed sites until a vendor patch is released.
  2. Restrict access to WordPress endpoints and administrative pages with network controls or WAF rules to block malicious requests.
  3. Enable and review web server and WordPress logs for unexpected shortcode or POST activity and known exploit indicators.
  4. Follow the vendor’s guidance and apply the official update as soon as a fixed version is published.

Frequently asked questions

Is CVE-2026-92229 being actively exploited?

Public exploit code is available for CVE-2026-92229, indicating easy exploitation by attackers.

Which Forminator Forms versions are affected by CVE-2026-92229?

The vulnerability affects the Forminator Forms 1.x branch, specifically versions 1.57.2 and earlier.

Is there a patch for CVE-2026-92229?

There is no fixed version listed for CVE-2026-92229; a vendor patch has not been provided in the supplied facts.

Does CVE-2026-92229 require authentication?

No, CVE-2026-92229 can be exploited without authentication against the Forminator Forms plugin.

References