CVE-2026-87069 Overview
CVE-2026-87069 affects the Forminator Forms WordPress plugin in versions prior to 1.57.2.1. The plugin fails to perform a nonce, capability, or ownership check before running a one-time payment-field migration during the construction of one of its admin screens. That construction executes on every wp-admin request for any logged-in user. Any authenticated user, including a Subscriber account with no plugin permissions, can rewrite the saved field configuration of any form on the site, including live payment forms. The weakness is classified as Missing Authorization [CWE-862].
Critical Impact
Low-privileged authenticated users can silently modify form configurations, including payment fields, without triggering permission checks.
Affected Products
- Forminator Forms WordPress plugin versions before 1.57.2.1
- WordPress sites exposing wp-admin to Subscriber-level accounts
- Sites using Forminator for payment collection through Stripe or PayPal fields
Discovery Timeline
- 2026-09-23 - CVE-2026-87069 published to the National Vulnerability Database
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-87069
Vulnerability Analysis
The flaw resides in the construction path of a Forminator admin screen. WordPress instantiates admin screen classes on every wp-admin request for authenticated sessions, regardless of the user role. Forminator uses this constructor to run a payment-field migration routine that rewrites stored form configuration.
Because the migration executes without a nonce verification, current_user_can() capability check, or ownership validation, the code path is reachable by any authenticated user. A Subscriber account, which by default has no plugin-related capabilities, can trigger the routine simply by requesting an admin page. The result is arbitrary modification of any form's saved field definition, including forms that collect payments.
Root Cause
The root cause is missing authorization [CWE-862] on a state-changing initialization path. Sensitive migration logic runs inside a class constructor tied to a broadly accessible admin screen. WordPress does not gate wp-admin access by role, so the constructor fires for every logged-in user. The plugin never validates whether the caller owns the target form or holds the capabilities required to modify it.
Attack Vector
An attacker needs a valid low-privilege account, such as a Subscriber on a site that allows open registration. After authenticating, the attacker issues a standard request to a wp-admin endpoint that instantiates the vulnerable admin screen. The migration routine then executes under the attacker's session and rewrites the stored field configuration for a targeted form. Attackers can weaponize this to alter payment destinations, tamper with pricing, or inject attacker-controlled field logic into checkout flows. See the WPScan Vulnerability Report for additional technical detail.
Detection Methods for CVE-2026-87069
Indicators of Compromise
- Unexpected modifications to Forminator form field definitions in the wp_postmeta or plugin-specific tables
- Payment forms whose configured Stripe or PayPal fields differ from the last known-good export
- wp-admin request activity from Subscriber-role accounts that would not normally browse admin screens
Detection Strategies
- Compare current Forminator form configurations against backups or version-controlled exports to identify unauthorized field changes
- Review WordPress access logs for wp-admin requests originating from low-privilege user sessions
- Audit the plugin version across all managed WordPress sites and flag any instance below 1.57.2.1
Monitoring Recommendations
- Enable file integrity and database-change monitoring for Forminator-related tables and options
- Alert on newly created Subscriber accounts followed by wp-admin navigation within the same session
- Track outbound payment configuration changes and reconcile them against authorized administrator activity
How to Mitigate CVE-2026-87069
Immediate Actions Required
- Update the Forminator Forms plugin to version 1.57.2.1 or later on every WordPress instance
- Disable open user registration temporarily if the site does not require Subscriber accounts
- Export and validate current form configurations, particularly any forms handling payments, against a trusted baseline
Patch Information
The vendor addressed the missing authorization issue in Forminator Forms version 1.57.2.1 by adding capability and context checks around the payment-field migration routine. Administrators should apply the update through the WordPress plugin dashboard or WP-CLI. Refer to the WPScan Vulnerability Report for advisory details.
Workarounds
- Restrict wp-admin access at the web server or WAF layer to trusted administrator IP ranges until the patch is applied
- Remove or downgrade unused Subscriber accounts and enforce strong registration controls
- Temporarily deactivate the Forminator plugin on sites that cannot immediately update, especially where payment forms are in use
# Update Forminator Forms via WP-CLI
wp plugin update forminator --version=1.57.2.1
# Verify installed version
wp plugin get forminator --field=version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
