Another Day, Another WordPress Hole: Forminator Joins The Security Merry-Go-Round
At this point, keeping a WordPress site secure is starting to feel less like website maintenance and more like playing Whac-A-Mole with a keyboard.
Patch one plugin, another vulnerability appears. Update that one, another security alert lands. Then a plugin you patched a few weeks ago suddenly needs another urgent update because researchers have found something else.
The latest example is Forminator, the popular WordPress forms plugin developed by WPMU DEV and installed on more than 600,000 websites.
Patchstack disclosed a high-priority vulnerability affecting Forminator versions up to and including 1.57.2, assigning it a CVSS score of 9.1. The flaw, tracked as CVE-2026-92229, involves unauthenticated arbitrary shortcode execution through the current_url parameter. Version 1.57.3 is listed as the patched release.
That alone would be concerning enough.
The bigger problem is that this is simply the latest entry in what has become a remarkable run of security fixes for the...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE