CVE-2026-87067

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Forminator Forms WordPress plugin before 1.57.2.1's own settings, so the issue is reachable well below administrator on sites that use that feature.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 2 mentions (2026-09-20); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-09-20: 2Mentions · 2026-09-21: 109-2009-21
Referenced assets3 URLs
Full discourse3 posts
  • NewNormal Security@NewScanTeam

    NewNormal Security turns CVEs since the previous batch into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 20 Sep 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📦 Missing authorization in a WordPress gallery plugin — any logged-in user reads image records they were never granted, including client proofing sets (NextGEN Gallery CVE-2026-81652, CVE-2026-81654) 📦 PHP object injection over XML-RPC — attacker-chosen classes instantiated inside the site (Forminator CVE-2026-87067) 🔎 Reverse-proxy admin panel now fingerprinted with its release — the box fronting a self-hosted estate appears in the inventory, so advisories against it can be matched (nginx-proxy-manager CVE-2026-93964) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #BrokenAccessControl #CSO #REDTEAM

    0100042
    7 followersView on X
  • ADK Cyber@ADKCyber

    CVE-2026-87067 (CVSS 8.5): Forminator Forms WordPress plugin before 1.57.2.1 has a deserialization issue via XML-RPC. Update if in use. https://nvd.nist.gov/vuln/detail/CVE-2026-87067 adkcyber… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/kLuKd5JIDK

    0000042
    96 followersView on X
  • Severity Daily@severitydaily

    Forminator’s 8.5 remote code execution on 600,000 WordPress sites shipped as one changelog line: “Fix: Security improvements.” The CVE landed three days later. No exploitation reported. https://severitydaily.com/forminator-cve-2026-87067-xml-rpc-object-injection-8-5-changelog-security-improvements/

    0000030
    24 followersView on X

Explore more