POCBIT

CVE-2026-92229 — Forminator ≤ 1.57.2 Unauthenticated Shortcode Execution

Unauthenticated arbitrary shortcode execution in **Forminator** (≤ 1.57.2) via **`current_url`** in quiz-related AJAX handlers.

#wordpress#forminator#shortcode#unauthenticated

CVE:

CVE-2026-92229

Date:

2026-09-25

Severity:

HIGH

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-92229 affects Forminator (≤ 1.57.2), a WordPress forms and quiz plugin. The current_url parameter in quiz AJAX endpoints is reported to allow unauthenticated shortcode execution.

Impact

Shortcode execution can expose secrets or achieve code execution depending on installed shortcodes and WordPress hardening.

Remediation

Update Forminator to the latest vendor release. Disable unused quiz modules if you cannot patch immediately.

Legal and ethical use

Use bundled tools only on WordPress sites you own or have written authorization to test. Unauthorized scanning or exploitation is illegal in most jurisdictions.

References

  • Look up the CVE ID on NVD and the CVE Program for official records.
  • Apply vendor/plugin updates from the official repository or vendor advisory before relying on any PoC.