CVE-2026-87067 | Forminator Forms Plugin up to 1.57.1 on WordPress XML-RPC code injection

SecurityVulns

A vulnerability was found in Forminator Forms Plugin up to 1.57.1 on WordPress. It has been declared as problematic. The impacted element is an unknown function of the component XML-RPC. Such manipulation leads to code injection.

This vulnerability is listed as CVE-2026-87067. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More