What is CVE-2026-12998?
This vulnerability affects the Forminator Forms plugin for WordPress up to version 1.55.0.2, allowing Insecure Direct Object Reference via the 'draft' parameter due to missing validation on a user-controlled key. This makes it possible for unauthenticated attackers to access or modify other users' draft submissions. Updating to the latest version is strongly recommended.
Azərbaycanca: Bu CVE WordPress-in Forminator Forms plaqininin 1.55.0.2 versiyasına qədər olan bütün versiyalarına təsir edən zəiflikdir. 'draft' parametri vasitəsilə İnsecure Direct Object Reference (IDOR) boşluğu yaradır, autentifikasiya olmamış istifadəçilərə başqalarının qaralama məlumatlarına müdaxilə etməyə imkan verir. Plaqini son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin does CVE-2026-12998 affect?
This vulnerability affects the Forminator Forms plugin for WordPress, all versions up to 1.55.0.2.
What can an attacker achieve by exploiting CVE-2026-12998?
Unauthenticated attackers can access or modify other users' draft submissions by exploiting the IDOR vulnerability via the 'draft' parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.