WordPress · Forminator · CVE-2026-12998
**Name of the Vulnerable Software and Affected Versions**
Forminator Forms – Contact Form, Payment Form & Custom Form Builder versions prior to 1.55.0.3
**Description**
An Insecure Direct Object Reference (IDOR) exists due to missing validation on a user-controlled key. This allows unauthenticated attackers to enumerate sequential integer entry IDs using the `draft` parameter to read saved draft form data from other users, including names, email addresses, phone numbers, addresses, and free-form message content. This issue is only exploitable on forms where the Save and Continue feature is enabled.
**Recommendations**
Update the plugin to a version newer than 1.55.0.2.
As a temporary mitigation, disable the Save and Continue feature on all forms to prevent the exploitation of the `draft` parameter.