{
  "id": 9164807,
  "title": "Another Day, Another WordPress Hole: Forminator Joins The Security Merry-Go-Round",
  "url": "https://urgent.news/2026/09/22/another-day-another-wordpress-hole-forminator-joins-the-security",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-22T13:01:36.000Z",
  "source": {
    "name": "HackerNoon",
    "slug": "hackernoon",
    "url": "https://hackernoon.com/another-day-another-wordpress-hole-forminator-joins-the-security-merry-go-round?source=rss"
  },
  "original_language": "en",
  "account": "In the ever-changing landscape of WordPress security, the Forminator plugin, developed by WPMU DEV, has joined the ranks of plugins plagued by frequent security vulnerabilities. Patchstack recently disclosed a high-priority, unauthenticated arbitrary shortcode execution flaw in Forminator versions up to and including 1.57.2, assigning it a CVSS score of 9.1. The vulnerability, identified as CVE-2026-92229, can be exploited through the current_url parameter. The developers released version 1.57.3 as the patched release to address this issue. However, Forminator's history is riddled with security fixes, totaling 51 patched vulnerabilities in its existence. These issues range from privilege escalation and arbitrary file upload to PHP object injection, stored cross-site scripting, information disclosure, and multisite-related security concerns. The sheer number of plugins in a typical website's ecosystem introduces more code, expanding the attack surface and creating additional dependencies. Each plugin, irrespective of its size, presents a potential vulnerability that can be exploited by attackers leveraging automated scanners. Website owners are increasingly finding it challenging to keep up with the update treadmill, as new vulnerabilities surface frequently. While developers may prioritize identifying and patching vulnerabilities, the impact on website administrators remains significant. The advice to keep WordPress, plugins, and themes updated has become incomplete, as vulnerabilities arise seemingly overnight. To enhance security, multiple layers of protection are necessary, including automatic vulnerability monitoring, regular updates, web application firewalls, removal of unused plugins, and robust backup strategies. For website owners using Forminator, it is crucial to update to version 1.57.3 or later to mitigate the risk posed by this critical vulnerability.",
  "summary": "51 patched vulnerabilities and counting: one popular WordPress plugin's history shows why \"just keep updating\" isn't enough anymore.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}