{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awpmu_devforminatorwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpmu_dev:forminator:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-92229"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Forminator (\u003c= 1.57.2)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["WPMU DEV"],"content_html":"\u003cp\u003eThe Forminator Forms - Contact Form, Payment Form \u0026amp; Custom Form Builder plugin for WordPress is affected by a critical vulnerability (CVE-2026-92229) impacting all versions up to and including 1.57.2. The vulnerability originates from a failure in the plugin to properly validate user-supplied input before passing it to the WordPress \u003ccode\u003edo_shortcode()\u003c/code\u003e function. By manipulating specific actions within the plugin, an unauthenticated attacker can force the application to execute arbitrary shortcodes. Because many WordPress plugins and themes register shortcodes that can perform sensitive operations, file modifications, or information disclosure, this flaw provides a vector for unauthorized system interaction. Depending on the environment and the shortcodes available in the installed plugin ecosystem, this can escalate to remote code execution (RCE) or full site compromise. Defenders should prioritize updating to the latest patched version and audit active shortcodes for potential exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary shortcodes within a WordPress environment. This can lead to unauthorized access to sensitive site data, unintended plugin configuration changes, or full system compromise if the target environment supports malicious or administrative shortcodes.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize updating the Forminator plugin to the latest version beyond 1.57.2 as soon as the vendor provides a patch. Perform a site-wide audit of all installed plugins and themes to identify and disable unnecessary shortcodes that could be triggered by this vulnerability. Monitor web server access logs for anomalous HTTP requests containing shortcode-related parameters or patterns consistent with WordPress plugin exploitation.\u003c/p\u003e\n","date_modified":"2026-09-19T04:08:46Z","date_published":"2026-09-19T04:08:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-forminator-shortcode-exec/","summary":"The Forminator plugin for WordPress contains an arbitrary shortcode execution vulnerability (CVE-2026-92229) allowing unauthenticated attackers to execute arbitrary shortcodes by leveraging improper input validation.","title":"Arbitrary Shortcode Execution in Forminator WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-forminator-shortcode-exec/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wpmu_dev:forminator:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}