Impact
The vulnerability allows any logged‑in WordPress user to trigger a migration of a Stripe payment field without performing a nonce, capability, or ownership check. During the construction of an admin screen, the plugin applies a one‑time update to the field configuration. Because the check is omitted, an attacker who can authenticate can rewrite the saved configuration of any form, including live payment forms.
Affected Systems
Affected systems are installations of the Forminator Forms WordPress plugin older than version 1.57.2.1; the vulnerability manifests on any site where an authenticated user accesses the wp‑admin interface.
Risk and Exploitability
The CVSS score is 3.1, indicating a low impact. The EPSS score is less than 1%, suggesting a low likelihood of public exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only that the target user is logged in; no privileged escalation or additional credentials are needed. Once authenticated, a Subscriber can invoke the migration and alter form settings, potentially compromising payment integrity.
OpenCVE Enrichment