{"id":"CVE-2026-87071","published":"2026-09-23T11:17:15.463","lastModified":"2026-09-23T18:13:31.210","description":"The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthenticated visitors submitting a public form that collects post content can attach metadata of their choosing to the post their submission creates.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-20"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/9d831b9d-c05d-4b9a-8b65-7e1e35e68510/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}