The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.55.0.2 via the 'draft' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate sequential integer entry IDs via the 'draft' parameter and read other users' saved draft form data, including names, email addresses, phone numbers, addresses, and free-form message content. This is only exploitable on forms that have the 'Save and Continue' feature enabled.
We have discovered 53,671 live websites that are affected by CVE-2026-12998.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 53,671 live websites (72% of Forminator install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 151 versions ( 97% of all versions) |
| 16,252 websites | |
| 4,151 websites | |
| 3,770 websites | |
| 3,474 websites | |
| 2,658 websites | |
| 1,661 websites | |
| 1,650 websites | |
| 1,592 websites | |
| 1,592 websites | |
| 1,452 websites |
| .com | 22,118 websites |
| .org | 2,531 websites |
| .co.uk | 2,415 websites |
| .de | 2,369 websites |
| .dk | 2,324 websites |
| .fr | 1,884 websites |
| .nl | 1,453 websites |
| .com.au | 1,272 websites |
| .it | 1,210 websites |
| .net | 966 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.com | *,*** | ||
| **************.com | **,*** | ||
| ******.com | **,*** | ||
| *****.com | **,*** | ||
| ********.org | **,*** | ||
| *******.com | **,*** | ||
| ************.com | **,*** | ||
| ********.com | **,*** | ||
| ***********.com | **,*** | ||
| *************.com | **,*** |
FAQ