WordPress Plugin Vulnerabilities

Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripe

Description

The plugin does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and that construction happens on every wp-admin request for any logged-in user. Any authenticated user, including a Subscriber with no permissions in the plugin, can therefore rewrite the saved field configuration of any form on the site, including a live payment form.

Proof of Concept

Affects Plugins

Fixed in 1.57.2.1

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes

Timeline

Publicly Published
2026-09-21 (about 2 days ago)
Added
2026-09-21 (about 1 day ago)
Last Updated
2026-09-21 (about 1 day ago)

Other