Description
The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and that construction happens on every wp-admin request for any logged-in user. Any authenticated user, including a Subscriber with no permissions in the Forminator Forms WordPress plugin before 1.57.2.1, can therefore rewrite the saved field configuration of any form on the site, including a live payment form.
Published: 2026-09-23
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Configuration Tampering
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows any logged‑in WordPress user to trigger a migration of a Stripe payment field without performing a nonce, capability, or ownership check. During the construction of an admin screen, the plugin applies a one‑time update to the field configuration. Because the check is omitted, an attacker who can authenticate can rewrite the saved configuration of any form, including live payment forms.

Affected Systems

Affected systems are installations of the Forminator Forms WordPress plugin older than version 1.57.2.1; the vulnerability manifests on any site where an authenticated user accesses the wp‑admin interface.

Risk and Exploitability

The CVSS score is 3.1, indicating a low impact. The EPSS score is less than 1%, suggesting a low likelihood of public exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only that the target user is logged in; no privileged escalation or additional credentials are needed. Once authenticated, a Subscriber can invoke the migration and alter form settings, potentially compromising payment integrity.

Generated by OpenCVE AI on September 23, 2026 at 15:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Forminator Forms to version 1.57.2.1 or later, which adds the missing nonce and capability checks.
  • If an upgrade is not immediately possible, restrict Subscriber role access to wp-admin or disable the migrate_stripe functionality via a custom filter or plugin.
  • Audit existing forms to ensure that no critical payment configuration has been inadvertently altered, and consider implementing an additional review process for form modifications.

Generated by OpenCVE AI on September 23, 2026 at 15:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and that construction happens on every wp-admin request for any logged-in user. Any authenticated user, including a Subscriber with no permissions in the Forminator Forms WordPress plugin before 1.57.2.1, can therefore rewrite the saved field configuration of any form on the site, including a live payment form.
Title Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripe
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T10:54:39.174Z

Reserved: 2026-09-08T19:03:14.848Z

Link: CVE-2026-87069

cve-icon Vulnrichment

Updated: 2026-09-23T10:35:00.535Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:04.450

Modified: 2026-09-23T11:17:15.157

Link: CVE-2026-87069

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:15:05Z

Weaknesses