CVE-2026-87067

CVE-2026-87067 published: The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing ...

View full NVD advisory → ← Back to CVE watch