Skip to main content
Vulnerability Database/CVE-2026-87069

CVE-2026-87069: Forminator Forms Authentication Bypass Flaw

CVE-2026-87069 is an authentication bypass flaw in Forminator Forms WordPress plugin that lets any logged-in user modify form configurations, including payment forms. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-87069 Overview

CVE-2026-87069 affects the Forminator Forms WordPress plugin in versions prior to 1.57.2.1. The plugin fails to perform a nonce, capability, or ownership check before running a one-time payment-field migration during the construction of one of its admin screens. That construction executes on every wp-admin request for any logged-in user. Any authenticated user, including a Subscriber account with no plugin permissions, can rewrite the saved field configuration of any form on the site, including live payment forms. The weakness is classified as Missing Authorization [CWE-862].

Critical Impact

Low-privileged authenticated users can silently modify form configurations, including payment fields, without triggering permission checks.

Affected Products

  • Forminator Forms WordPress plugin versions before 1.57.2.1
  • WordPress sites exposing wp-admin to Subscriber-level accounts
  • Sites using Forminator for payment collection through Stripe or PayPal fields

Discovery Timeline

  • 2026-09-23 - CVE-2026-87069 published to the National Vulnerability Database
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-87069

Vulnerability Analysis

The flaw resides in the construction path of a Forminator admin screen. WordPress instantiates admin screen classes on every wp-admin request for authenticated sessions, regardless of the user role. Forminator uses this constructor to run a payment-field migration routine that rewrites stored form configuration.

Because the migration executes without a nonce verification, current_user_can() capability check, or ownership validation, the code path is reachable by any authenticated user. A Subscriber account, which by default has no plugin-related capabilities, can trigger the routine simply by requesting an admin page. The result is arbitrary modification of any form's saved field definition, including forms that collect payments.

Root Cause

The root cause is missing authorization [CWE-862] on a state-changing initialization path. Sensitive migration logic runs inside a class constructor tied to a broadly accessible admin screen. WordPress does not gate wp-admin access by role, so the constructor fires for every logged-in user. The plugin never validates whether the caller owns the target form or holds the capabilities required to modify it.

Attack Vector

An attacker needs a valid low-privilege account, such as a Subscriber on a site that allows open registration. After authenticating, the attacker issues a standard request to a wp-admin endpoint that instantiates the vulnerable admin screen. The migration routine then executes under the attacker's session and rewrites the stored field configuration for a targeted form. Attackers can weaponize this to alter payment destinations, tamper with pricing, or inject attacker-controlled field logic into checkout flows. See the WPScan Vulnerability Report for additional technical detail.

Detection Methods for CVE-2026-87069

Indicators of Compromise

  • Unexpected modifications to Forminator form field definitions in the wp_postmeta or plugin-specific tables
  • Payment forms whose configured Stripe or PayPal fields differ from the last known-good export
  • wp-admin request activity from Subscriber-role accounts that would not normally browse admin screens

Detection Strategies

  • Compare current Forminator form configurations against backups or version-controlled exports to identify unauthorized field changes
  • Review WordPress access logs for wp-admin requests originating from low-privilege user sessions
  • Audit the plugin version across all managed WordPress sites and flag any instance below 1.57.2.1

Monitoring Recommendations

  • Enable file integrity and database-change monitoring for Forminator-related tables and options
  • Alert on newly created Subscriber accounts followed by wp-admin navigation within the same session
  • Track outbound payment configuration changes and reconcile them against authorized administrator activity

How to Mitigate CVE-2026-87069

Immediate Actions Required

  • Update the Forminator Forms plugin to version 1.57.2.1 or later on every WordPress instance
  • Disable open user registration temporarily if the site does not require Subscriber accounts
  • Export and validate current form configurations, particularly any forms handling payments, against a trusted baseline

Patch Information

The vendor addressed the missing authorization issue in Forminator Forms version 1.57.2.1 by adding capability and context checks around the payment-field migration routine. Administrators should apply the update through the WordPress plugin dashboard or WP-CLI. Refer to the WPScan Vulnerability Report for advisory details.

Workarounds

  • Restrict wp-admin access at the web server or WAF layer to trusted administrator IP ranges until the patch is applied
  • Remove or downgrade unused Subscriber accounts and enforce strong registration controls
  • Temporarily deactivate the Forminator plugin on sites that cannot immediately update, especially where payment forms are in use
bash
# Update Forminator Forms via WP-CLI
wp plugin update forminator --version=1.57.2.1

# Verify installed version
wp plugin get forminator --field=version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.