External risk intelligence

Forminator WordPress Plugin Arbitrary Shortcode Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-92229

The vulnerability exists in a WordPress plugin designed to create contact, payment, and custom forms. These components are intentionally deployed on public-facing web pages to interact with site visitors, making the affected functionality accessible via the public internet by design.

Code Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Forminator Forms plugin for WordPress, impacting its ability to handle user-submitted data. This flaw allows unauthorized individuals to potentially execute harmful commands on affected systems by submitting specially crafted requests. The main concern at this time is confirming if this plugin is in use and identifying any potential exposure.

  • Unauthenticated attackers can run unauthorized commands.
  • Affects user-facing form submissions.
  • Confirm plugin use and assess exposure.

Attack Path

How an attacker could exploit the issue

Attackers can exploit this vulnerability by submitting crafted input to the Forminator plugin on a WordPress site, as the plugin does not adequately validate user-provided data before processing it. This allows an unauthenticated attacker to execute arbitrary shortcodes, which could lead to unauthorized actions or data exposure on the affected site.

  • Accessible via the public internet.
  • Unauthenticated user input triggers shortcode execution.
  • Potential for arbitrary code execution and data compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to execute arbitrary shortcodes on a WordPress site. This may occur when the system processes user-supplied input without proper validation before executing shortcodes, potentially affecting site content and behavior.

  • WordPress site content and behavior.
  • Unauthenticated shortcode execution.
  • Compromised site integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

Owners of WordPress sites utilizing the Forminator plugin are responsible for addressing this vulnerability. The immediate first step is to inventory all WordPress deployments, identify those using Forminator, and then confirm the reachability and business criticality of these sites. Once confirmed, the accountable owner for each instance should be determined to plan appropriate remediation actions, prioritizing the most exposed or critical systems.

  • WordPress site owners should manage this issue.
  • Verify all Forminator plugin installations.
  • Plan remediation based on site criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Forminator Forms plugin used for?

Forminator is a tool for WordPress sites that lets administrators build interactive elements like contact forms, payment gateways, and custom data-collection modules. Because these forms are designed to gather information from site visitors, they are typically embedded directly into web pages that are visible to the public.

What does CVE-2026-92229 mean by arbitrary shortcode execution?

This vulnerability, classified as CWE-94, involves improper control of code generation. In WordPress, shortcodes are small snippets of text that trigger complex functions. Because the plugin fails to check user input before running these commands, an attacker can input their own malicious shortcodes, tricking the site into executing unauthorized actions or revealing sensitive data.

How is this vulnerability triggered by an attacker?

An attacker triggers the flaw by submitting specifically crafted input through the plugin's form interfaces. The bug relies on the plugin's failure to sanitize this input before processing it. Importantly, this does not require a user to have a login account or administrative privileges to the WordPress site; the system processes the request regardless of the user's authentication status.

Is my site at risk according to Halo Surface Signal?

Yes, Halo Surface Signal identifies this as a high-priority issue because Forminator plugins are, by design, deployed on public-facing web pages to receive input from the internet. Since the functionality is intentionally accessible to site visitors, there is no requirement for an attacker to have specialized network access; they only need to reach your website.

What should I do if I use Forminator on my site?

First, conduct an inventory of all your WordPress instances to verify if and where the Forminator plugin is installed. Once you have identified these sites, assess their business importance and public reachability. Identify the specific owners for each instance to coordinate an update or other necessary protective measures based on the criticality of the site.

References