CVE-2026-87070 Details
Description
The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwarding headers over the connecting address, and it uses that value both to enforce its per-visitor voting limit and to record who submitted an entry. Unauthenticated visitors can therefore vote without limit on any poll and can choose the address stored against every submission they make.
A vulnerability exists in the Forminator Forms WordPress plugin in versions prior to 1.57.2.1. The issue arises because the plugin does not properly verify if a request comes from a trusted proxy. As a result, it incorrectly prioritizes client-supplied forwarding headers over the actual connecting address. This flaw allows unauthenticated visitors to bypass per-visitor voting limits, enabling them to vote without restriction on any poll. Additionally, they can manipulate the address associated with their submissions.
Users are advised to update the Forminator Forms WordPress plugin to version 1.57.2.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/3206e88e-5d29-4897-863e-101dc9b33ec5/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-348 | Use of Less Trusted Source | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Forminator Forms | < 1.57.2.1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | New CVE Received | [email protected] |
| Sep 23, 2026 | CVE Modified | CISA-ADP |
Volerion