CVE-2026-92229 — Forminator ≤ 1.57.2 Unauthenticated Shortcode Execution
Unauthenticated arbitrary shortcode execution in **Forminator** (≤ 1.57.2) via **`current_url`** in quiz-related AJAX handlers.
#wordpress#forminator#shortcode#unauthenticated
Description
Overview
CVE-2026-92229 affects Forminator (≤ 1.57.2), a WordPress forms and quiz plugin. The current_url parameter in quiz AJAX endpoints is reported to allow unauthenticated shortcode execution.
Impact
Shortcode execution can expose secrets or achieve code execution depending on installed shortcodes and WordPress hardening.
Remediation
Update Forminator to the latest vendor release. Disable unused quiz modules if you cannot patch immediately.
Legal and ethical use
Use bundled tools only on WordPress sites you own or have written authorization to test. Unauthorized scanning or exploitation is illegal in most jurisdictions.
References
- Look up the CVE ID on NVD and the CVE Program for official records.
- Apply vendor/plugin updates from the official repository or vendor advisory before relying on any PoC.