
CVE-2026-12998 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … https://www.cve.org/CVERecord?id=CVE-2026-12998
Post summary
The post announces that the Forminator Forms plugin for WordPress is vulnerable to an Insecure Direct Object Reference across all versions up to the date indicated, but provides no PoC, exploit code, or remediation details.
