Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail configuration to any address, carrying a link of their choosing inside the site's own template. The token that authorises the send is handed to the anonymous caller by the Forminator Forms WordPress plugin before 1.57.2.1 itself and can be replayed without limit. | |
| Title | Forminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sending with Attacker-Controlled Link | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:54:24.744Z
Reserved: 2026-09-08T19:05:47.054Z
Link: CVE-2026-87074
Updated: 2026-09-23T10:34:50.600Z
Status : Received
Published: 2026-09-23T06:17:04.557
Modified: 2026-09-23T11:17:15.593
Link: CVE-2026-87074
No data.
OpenCVE Enrichment
No data.