chiprook
← Security
SecuritySeptember 22, 2026, 20:01

Forminator WordPress plugin hit by 9.1-severity vulnerability

Patchstack disclosed CVE-2026-92229 in the Forminator WordPress plugin affecting versions up to and including 1.57.2, rated CVSS 9.1. The flaw allows unauthenticated arbitrary shortcode execution via the current_url parameter, and is fixed in version 1.57.3. The plugin runs on more than 600,000 websites.

Forminator WordPress plugin hit by 9.1-severity vulnerability
#WordPress#Forminator#Patchstack
Read next
Security

Western Australia Police report 900K facial scans in 3-month LFR trial

Security

Check Point warns of Management Server zero-day exploited in attacks

Security

University of Toronto researchers amplify Rowhammer attacks on ECC-protected GPUs

Security

91% of workers feel stressed at work over IT security risks