PT-2026-97184 · WordPress · Forminator Forms
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Forminator Forms WordPress plugin versions prior to 1.57.2.1
Description
The plugin fails to perform a nonce, capability, or ownership check before executing a one-time payment-field migration during the construction of an admin screen. This process occurs on every wp-admin request for any logged-in user. Consequently, any authenticated user, including those with Subscriber roles and no specific permissions within the plugin, can rewrite the saved field configuration of any form on the site, including active payment forms. A nonce is a unique token used to protect against cross-site request forgery (CSRF) attacks.
Recommendations
Update Forminator Forms WordPress plugin to version 1.57.2.1 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forminator Forms