PT-2026-38324 · WordPress · Forminator Forms
Anhcd05
·
Published
2026-05-07
·
Updated
2026-05-07
·
CVE-2026-6222
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Forminator Forms versions prior to 1.52.0
Description
The
processRequest() function in Forminator Admin Module Edit Page fails to verify if the current user possesses the manage forminator modules capability before executing sensitive module-management actions. These actions include exporting, deleting, cloning, deleting entries, and changing publish/draft status. The system relies solely on a nonce check using the forminator form request variable, which is available in the global forminatorData JavaScript object on all admin pages. Since the function is triggered during the admin menu action hook before page-level capability checks are enforced, authenticated attackers with low-privilege roles, such as subscribers, can craft POST requests to export internal configurations (including integration credentials and notification routing), delete modules, or remove all submissions and votes.Recommendations
Update to a version later than 1.51.1.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forminator Forms