CyberRota Analysis
AI-GeneratedAn unauthenticated PHP Object Injection vulnerability exists in Forminator versions up to and including 1.57.0, allowing attackers to exploit this flaw to execute arbitrary code on the server. This critical vulnerability poses a significant risk to any system using the affected versions, as it can lead to full system compromise. Organizations utilizing Forminator should prioritize immediate patching or mitigation efforts to safeguard their environments.
CVE
CVE-2026-66583
Severity
CRITICAL
CVSS
9.8
EPSS
0.39%
Original NVD Description
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.