Plugin Vulnerability Hub
Plugin 37 known issues Latest disclosed Feb 22, 2026

Forminator Forms – Contact Form, Payment Form & Custom Form Builder Vulnerabilities

Review known vulnerability records for the WordPress plugin Forminator Forms – Contact Form, Payment Form & Custom Form Builder (`forminator`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-32409, CVE-2026-2002 and CVE-2025-14782, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
37
High or Critical
9
Patch Coverage
100%
Last Updated
Apr 15, 2026
Priority CVE Quick Links

Fast paths into Forminator Forms – Contact Form, Payment Form & Custom Form Builder CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
34
CVE-2024-28890 Critical 1.29.0
CVE-2024-28890 Forminator Forms – Contact Form, Payment Form & Custom Form Builder Remote Code Execution

Forminator <= 1.28.1 - Unauthenticated Arbitrary File Upload

CVE-2023-4596 Critical 1.25.0
CVE-2023-4596 Forminator Forms – Contact Form, Payment Form & Custom Form Builder Remote Code Execution

Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload

CVE-2024-31077 Critical 1.29.3
CVE-2024-31077 Forminator Forms – Contact Form, Payment Form & Custom Form Builder SQL Injection

Forminator <= 1.29.2 - Authenticated (Admin+) SQL Injection

CVE-2025-6463 High 1.44.3
CVE-2025-6463 Forminator Forms – Contact Form, Payment Form & Custom Form Builder Remote Code Execution

Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion

CVE-2025-6464 High 1.44.3
CVE-2025-6464 Forminator Forms – Contact Form, Payment Form & Custom Form Builder Vulnerability

Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion

CVE-2024-10402 High 1.36.0
CVE-2024-10402 Forminator Forms – Contact Form, Payment Form & Custom Form Builder Vulnerability

Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation

CVE-2024-7389 High 1.29.2
CVE-2024-7389 Forminator Forms – Contact Form, Payment Form & Custom Form Builder Sensitive Information Exposure

Forminator <= 1.29.1 - HubSpot Developer API Key Sensitive Information Exposure

CVE-2024-1794 High 1.29.1
CVE-2024-1794 Forminator Forms – Contact Form, Payment Form & Custom Form Builder File Upload

Forminator <= 1.29.0 - Unauthenticated Stored Cross-Site Scripting via File Upload

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Forminator Forms – Contact Form, Payment Form & Custom Form Builder so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
37 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
3 critical and 6 high severity findings.
Recent CVEs
CVE-2026-32409, CVE-2026-2002 and CVE-2025-14782
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Forminator Forms – Contact Form, Payment Form & Custom Form Builder

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-32409
CVE-2026-32409: Forminator <= 1.50.2 - Missing Authorization

The Forminator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.50.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Published
Feb 22, 2026
Patched Release
1.50.3
Affected Versions
Versions up to 1.50.2
Next Step
Update to 1.50.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-2002
CVE-2026-2002: Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.50.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form_name parameter in all versions up to, and including, 1.50.2 due to insufficient input sanitization and output escaping. This make...

Published
Feb 16, 2026
Patched Release
1.50.3
Affected Versions
Versions up to 1.50.2
Next Step
Update to 1.50.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-14782
CVE-2025-14782: Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.49.1 - Missing Authorization to Authenticated (Forminator User+) CSV Export

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.49.1 via the 'listen_for_csv_export' function. This is due to the plugin not properly verifying that a user i...

Published
Jan 08, 2026
Patched Release
1.49.2
Affected Versions
Versions up to 1.49.1
Next Step
Update to 1.49.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-7638
CVE-2025-7638: Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.45.0 - Authenticated (Administrator+) SQL Injection via `order_by` Parameter

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and including, 1.45.0 due to insufficient escaping on the user supplied parameter and lack of...

Published
Jul 17, 2025
Patched Release
1.45.1
Affected Versions
Versions up to 1.45.0
Next Step
Update to 1.45.1 or newer if supported.
Plugin High Patched: Yes CVE-2025-6464
CVE-2025-6464: Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via deserialization of untrusted input in the 'entry_delete_upload_files' function. This makes it possib...

Published
Jul 01, 2025
Patched Release
1.44.3
Affected Versions
Versions up to 1.44.2
Next Step
Update to 1.44.3 or newer if supported.
Plugin High Patched: Yes CVE-2025-6463
CVE-2025-6463: Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'entry_delete_upload_files' function in all versions up to, and including, 1.44.2. This makes it p...

Published
Jul 01, 2025
Patched Release
1.44.3
Affected Versions
Versions up to 1.44.2
Next Step
Update to 1.44.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-5341
CVE-2025-5341: Forminator <= 1.44.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via id and data-size Parameters

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id' and 'data-size’ parameters in all versions up to, and including, 1.44.1 due to insufficient input sanitization and output escapin...

Published
Jun 04, 2025
Patched Release
1.44.2
Affected Versions
Versions up to 1.44.1
Next Step
Update to 1.44.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-3487
CVE-2025-3487: Forminator <= 1.42.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'limit'

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘limit’ parameter in all versions up to, and including, 1.42.0 due to insufficient input sanitization and output escaping. This makes...

Published
Apr 16, 2025
Patched Release
1.42.1
Affected Versions
Versions up to 1.42.0
Next Step
Update to 1.42.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-3479
CVE-2025-3479: Forminator <= 1.42.0 - Order Replay Vulnerability

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 1.42.0 via the 'handle_stripe_single' function due to insufficient validation on a user controlled key. This makes it p...

Published
Apr 16, 2025
Patched Release
1.42.1
Affected Versions
Versions up to 1.42.0
Next Step
Update to 1.42.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-0469
CVE-2025-0469: Forminator <= 1.39.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider template data in all versions up to, and including, 1.39.2 due to insufficient input sanitization and output escaping. This mak...

Published
Feb 26, 2025
Patched Release
1.39.3
Affected Versions
1.39.2 through 1.39.2
Next Step
Update to 1.39.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-0470
CVE-2025-0470: Forminator <= 1.38.2 - Reflected Cross-Site Scripting via Title Parameter

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the title parameter in all versions up to, and including, 1.38.2 due to insufficient input sanitization and output escaping. This makes...

Published
Jan 30, 2025
Patched Release
1.38.3
Affected Versions
Versions up to 1.38.2
Next Step
Update to 1.38.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-7052
CVE-2024-7052: Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.38.2 - Authenticated (Admin+) Stored Cross-Site Scripting

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.38.2 due to insufficient input sanitization and output escaping. This makes it poss...

Published
Jan 24, 2025
Patched Release
1.38.3
Affected Versions
Versions up to 1.38.2
Next Step
Update to 1.38.3 or newer if supported.