Forminator WordPress plugin hit by 9.1-severity vulnerability
Patchstack disclosed CVE-2026-92229 in the Forminator WordPress plugin affecting versions up to and including 1.57.2, rated CVSS 9.1. The flaw allows unauthenticated arbitrary shortcode execution via the current_url parameter, and is fixed in version 1.57.3. The plugin runs on more than 600,000 websites.
- CVE-2026-92229 carries a CVSS score of 9.1
- Exploitation needs no authentication via current_url parameter
- Fix shipped in Forminator 1.57.3 on September 17
- Plugin is installed on over 600,000 websites
Read next
Security