📦 Forminator

by Incsub

🔍 What is Forminator?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-4596

CRITICAL CVSS 9.8 Aug 30, 2023

The Forminator WordPress plugin up to version 1.24.6 has a critical file upload vulnerability where unauthenticated attackers can upload arbitrary files to the server. This occurs because file type va...

CVE-2025-6464

HIGH CVSS 7.5 Jul 2, 2025

The Forminator WordPress plugin is vulnerable to PHP Object Injection via deserialization of untrusted input when form submissions are deleted. This allows unauthenticated attackers to inject maliciou...

CVE-2025-6463

HIGH CVSS 8.8 Jul 2, 2025

The Forminator WordPress plugin has a critical vulnerability that allows unauthenticated attackers to delete arbitrary files on the server by manipulating form submissions. This affects all versions u...

CVE-2024-31077

HIGH CVSS 7.2 Apr 23, 2024

This SQL injection vulnerability in Forminator WordPress plugin allows remote authenticated attackers with administrative privileges to execute arbitrary SQL commands. Attackers can read, modify, or d...

CVE-2024-29777

HIGH CVSS 7.1 Mar 27, 2024

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Forminator WordPress plugin. When users visit a specially crafted URL, the scripts execute in their brow...