CVE-2026-87070 PUBLISHED

Forminator Forms < 1.57.2.1 - Unauthenticated Poll Vote Limit Bypass via IP Spoofing

Assigner: WPScan
Reserved: 08.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwarding headers over the connecting address, and it uses that value both to enforce its per-visitor voting limit and to record who submitted an entry. Unauthenticated visitors can therefore vote without limit on any poll and can choose the address stored against every submission they make.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor Unknown
Product Forminator Forms
Versions Default: unaffected
  • affected from 0 to 1.57.2.1 (excl.)

Credits

  • vuxvinh finder
  • WPScan coordinator

References

Problem Types

  • CWE-348 Use of Less Trusted Source CWE