DIRAS TAKE
Urgent: public exploit code exists, so patching or mitigations should be prioritised immediately; treat internet-facing WordPress sites with this plugin as exposed. Apply access restrictions and monitoring now and install the vendor fix as soon as it is released.
What is CVE-2026-92229?
An unauthenticated attacker can execute arbitrary shortcodes on sites running the Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin, enabling remote code paths via WordPress shortcode handling. CVE-2026-92229 affects the 1.x branch, specifically versions 1.57.2 and earlier. Exploitation requires only network access to a site hosting the vulnerable plugin and no valid account or user interaction.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Which versions of wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.57.2 and earlier |
Is CVE-2026-92229 being exploited?
Public exploit code is available.
How to fix CVE-2026-92229
- Remove or deactivate the Forminator Forms plugin on exposed sites until a vendor patch is released.
- Restrict access to WordPress endpoints and administrative pages with network controls or WAF rules to block malicious requests.
- Enable and review web server and WordPress logs for unexpected shortcode or POST activity and known exploit indicators.
- Follow the vendor’s guidance and apply the official update as soon as a fixed version is published.
Frequently asked questions
Is CVE-2026-92229 being actively exploited?
Public exploit code is available for CVE-2026-92229, indicating easy exploitation by attackers.
Which Forminator Forms versions are affected by CVE-2026-92229?
The vulnerability affects the Forminator Forms 1.x branch, specifically versions 1.57.2 and earlier.
Is there a patch for CVE-2026-92229?
There is no fixed version listed for CVE-2026-92229; a vendor patch has not been provided in the supplied facts.
Does CVE-2026-92229 require authentication?
No, CVE-2026-92229 can be exploited without authentication against the Forminator Forms plugin.
References
- nvd.nist.gov/vuln/detail/CVE-2026-92229
- cve.org/CVERecord?id=CVE-2026-92229
- wordfence.com/threat-intel/vulnerabilities/id/7c28869c-c880-4322-9f17-09495a08576e?source=cve
- plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/modules/quizzes/front/front-action.php#L870
- plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/modules/quizzes/front/front-action.php#L837
- plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/modules/quizzes/front/front-action.php#L60
- plugins.trac.wordpress.org/browser/forminator/tags/1.57.2/library/abstracts/abstract-class-front-action.php#L127
- plugins.trac.wordpress.org/changeset?reponame=&old=3700724%40forminator&new=3700724%40forminator
- All wpmudev CVEs on CVE Radar
- CVEs published in September 2026