Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and that construction happens on every wp-admin request for any logged-in user. Any authenticated user, including a Subscriber with no permissions in the Forminator Forms WordPress plugin before 1.57.2.1, can therefore rewrite the saved field configuration of any form on the site, including a live payment form. | |
| Title | Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripe | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:54:39.174Z
Reserved: 2026-09-08T19:03:14.848Z
Link: CVE-2026-87069
Updated: 2026-09-23T10:35:00.535Z
Status : Received
Published: 2026-09-23T06:17:04.450
Modified: 2026-09-23T11:17:15.157
Link: CVE-2026-87069
No data.
OpenCVE Enrichment
Updated: 2026-09-23T15:15:05Z
-
CWE-862
Missing Authorization