Vulnerability
Published 2026-10-08
Verified 2026-10-11

WordPress: Forminator (600,000+ installs) lets unauthenticated visitors delete content (CVE-2026-65459, CVSS 7.5, fix 1.58.0); 14 premium ThemeREX, AncoraThemes, axiomthemes and Elated themes carry unauthenticated PHP object injection or file inclusion (up to 9.8) with no patched version listed

Patchstack published a batch of WordPress advisories on 8 October 2026, and the CVE records (Patchstack as CVE numbering authority) followed on 10 October. The most widely deployed is CVE-2026-65459 in Forminator, the WPMU DEV form builder with more than 600,000 active installs on WordPress.org: versions up to 1.57.3 have a broken access control flaw that lets an unauthenticated attacker delete arbitrary content, rated CVSS 3.1 7.5 and high priority. It was reported by Ananda Dhakal of Patchstack on 3 September and is fixed in 1.58.0 (released 7 October). The same batch lists unauthenticated PHP object injection, rated 9.8, in 13 commercial themes: ThemeREX Buzz Stone (up to 1.0.2), Photolia (1.0.3), Jacqueline (2.22), Alliance (3.11), ShiftCV (3.0.14), Windsor (2.10), Education Center (3.6.12) and Asia Garden (1.3.1); AncoraThemes Qwery (3.6.1), Anesta (1.5.3) and Drone Media (2.2.0); and axiomthemes Kicker (2.2.1), Original (1.9.0) and FC United (1.1.1), plus an unauthenticated local file inclusion (8.1) in Elated-Themes Ambient (up to 1.7). Patchstack lists no patched version for any of these themes, and some were reported as early as February. PHP object injection only becomes code execution when a usable gadget chain is present in the site's plugins or themes, but the 9.8 rating reflects that worst case. Also in the batch: Creator LMS up to 1.2.21, contributor-level arbitrary file upload rated 9.9, fixed in 1.2.22, and WooCommerce Multilingual & Multicurrency up to 5.5.8, PHP object injection by a Shop manager rated 7.2, fixed in 5.6.3. No exploitation has been reported. Primary: Patchstack advisories; CVE records.

Product
WordPress: Forminator (WPMU DEV); premium themes from ThemeREX, AncoraThemes, axiomthemes and Elated-Themes; Creator LMS; WooCommerce Multilingual & Multicurrency
Versions
Forminator <= 1.57.3; ThemeREX Buzz Stone <= 1.0.2, Photolia <= 1.0.3, Jacqueline <= 2.22, Alliance <= 3.11, ShiftCV <= 3.0.14, Windsor <= 2.10, Education Center <= 3.6.12, Asia Garden <= 1.3.1; AncoraThemes Qwery <= 3.6.1, Anesta <= 1.5.3, Drone Media <= 2.2.0; axiomthemes Kicker <= 2.2.1, Original <= 1.9.0, FC United <= 1.1.1; Elated Ambient <= 1.7; Creator LMS <= 1.2.21; WooCommerce Multilingual & Multicurrency <= 5.5.8
CVSS
Forminator 7.5; themes 9.8 (Ambient 8.1); Creator LMS 9.9; WooCommerce Multilingual 7.2 (CVSS 3.1, Patchstack)
Exploited in Australia?
unknown
Patch to
Update Forminator to 1.58.0, Creator LMS to 1.2.22 and WooCommerce Multilingual & Multicurrency to 5.6.3 or later. For the listed themes there is no fixed version yet: ask the theme vendor for an update, switch away from the theme if it is unmaintained, or put a web application firewall rule in front of the site, and check for unexpected admin users or files.

Primary: Patchstack — Forminator <= 1.57.3 Arbitrary Content Deletion (CVE-2026-65459, published 8 Oct 2026) · Vendor: Forminator changelog on WordPress.org (1.58.0, 7 Oct 2026) · CVE: CVE-2026-65459 · Patchstack — Education Center theme <= 3.6.12 PHP Object Injection (CVE-2026-66483, 9.8, no patched version listed); one of 14 theme advisories

vulnerabilities