Extension WordPress
Vulnérabilités Forminator Forms – Contact Form, Payment Form & Custom Form Builder, page 2
Cette page rassemble les failles publiées pour Forminator Forms – Contact Form, Payment Form & Custom Form Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Forminator Forms – Contact Form, Payment Form & Custom Form Builder
53 fiches
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 – Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via deserialization of untrusted input in the 'entry_delete_upload_files' function.…
*-1.44.2
1.44.3
01/07/2025
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 – Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'entry_delete_upload_files' function in all versions up to, and including,…
*-1.44.2
1.44.3
01/07/2025
Forminator <= 1.44.1 – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via id and data-size Parameters
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id' and 'data-size’ parameters in all versions up to, and including, 1.44.1 due to insufficient…
*-1.44.1
1.44.2
04/06/2025
Forminator <= 1.42.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'limit'
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘limit’ parameter in all versions up to, and including, 1.42.0 due to insufficient input sanitization…
*-1.42.0
1.42.1
17/04/2025
Forminator <= 1.42.0 – Order Replay Vulnerability
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 1.42.0 via the 'handle_stripe_single' function due to insufficient validation on a…
*-1.42.0
1.42.1
17/04/2025
Forminator <= 1.39.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider template data in all versions up to, and including, 1.39.2 due to insufficient input…
1.39.2
1.39.3
26/02/2025
Forminator <= 1.38.2 – Reflected Cross-Site Scripting via Title Parameter
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the title parameter in all versions up to, and including, 1.38.2 due to insufficient input sanitization…
*-1.38.2
1.38.3
30/01/2025
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.38.2 – Authenticated (Admin+) Stored Cross-Site Scripting
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.38.2 due to insufficient input sanitization and…
*-1.38.2
1.38.3
24/01/2025
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.36.0 – Insecure Direct Object Reference to Submission Manipulation
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.36.0 via the submit_quizzes() function due to missing validation…
*-1.36.0
1.36.1
30/10/2024
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 – Missing Authorization to Authenticated (Contributor+) Form Update and Creation
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This…
*-1.35.1
1.36.0
25/10/2024
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 – Cross-Site Request Forgery to Draft Quiz Creation
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.35.1. This is due to missing or incorrect nonce validation…
*-1.35.1
1.36.0
16/10/2024
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 – Cross-Site Request Forgery to Draft Custom Form Creation
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.35.1. This is due to missing or incorrect nonce validation…
*-1.35.1
1.36.0
16/10/2024
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.34.0 – Reflected Cross-Site Scripting
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.34.0 due to insufficient input sanitization and output escaping. This…
*-1.34.0
1.34.1
09/09/2024
Forminator <= 1.29.1 – HubSpot Developer API Key Sensitive Information Exposure
The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated attackers to extract the HubSpot integration developer API key and make…
*-1.29.1
1.29.2
01/08/2024
Forminator <= 1.15.2 – Reflected Cross-Site Scripting
The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.15.2 due to insufficient input sanitization and output escaping. This makes…
*-1.15.2
1.15.4
18/04/2024
Forminator <= 1.28.1 – Unauthenticated Arbitrary File Upload
The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.28.1. This makes it possible…
*-1.28.1
1.29.0
18/04/2024
Forminator <= 1.29.2 – Authenticated (Admin+) SQL Injection
The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.29.2 due to insufficient escaping on the user…
*-1.29.2
1.29.3
18/04/2024
Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.29.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via forminator_form Shortcode
The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ forminator_form shortcode attribute in versions up to, and including, 1.29.2 due to insufficient input sanitization…
*-1.29.2
1.29.3
08/04/2024
Forminator <= 1.29.0 – Unauthenticated Stored Cross-Site Scripting via File Upload
The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) in all versions up to, and including, 1.29.0 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.29.0
1.29.1
29/03/2024
Forminator <= 1.29.0 – Reflected Cross-Site Scripting
The Forminator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.29.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-1.29.0
1.29.1
25/03/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.