CVE-2026-6222: Forminator Forms <= 1.51.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'forminator_action' Parameter
The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the processRequest() method in ForminatorAdminModuleEditPage (admin/abstracts/class-admin-module-edit-page.php) dispatching sensitive module-management actions — including export, delete, clone, delete-entries, publish/draft, and bulk variants — after only a nonce check, without ever verifying that the current user holds the manageforminatormodules capability. The nonce used (forminatorformrequest) is unconditionally embedded in the global forminatorData JavaScript object and localized on every Forminator admin page, including Templates and Reports pages accessible to users who explicitly lack module-management permissions. Because processRequest() is invoked during the adminmenu action hook — which fires before WordPress enforces page-level capability checks — a user whose Forminator role is restricted to Templates or Reports can craft a valid POST request targeting any published module and successfully trigger the vulnerable actions. This makes it possible for authenticated attackers with subscriber-level access (or any custom low-privilege Forminator role) to export the complete internal configuration of arbitrary forms/polls/quizzes (including notification routing, integration credentials, and conditional logic), delete modules, delete all submissions/votes, clone modules, or bulk-change publish/draft status.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Forminator Formsto a version that resolves this vulnerability.Fixed in 1.51.1 - Configuration
In Forminator's processRequest() dispatcher for Forminator_Admin_Module_Edit_Page, add/ensure a capability check for manage_forminator_modules before executing sensitive module-management actions (export, delete, clone, delete-entries, publish/draft, and bulk variants).
Forminator_Admin_Module_Edit_Page (processRequest) manage_forminator_modules capability check for module-management actions (export, delete, clone, delete-entries, publish/draft, bulk variants) = required - Compensating control
Restrict access to Forminator module-management admin pages (including Templates and Reports pages where the forminatorData JS object and forminator_form_request nonce are localized) so that only users who have the manage_forminator_modules capability can reach them.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6222?
CVE-2026-6222 has been classified as a medium severity vulnerability due to its potential for unauthorized access to sensitive information.
How do I fix CVE-2026-6222?
To mitigate CVE-2026-6222, update the Forminator Forms plugin to version 1.51.2 or later immediately.
What causes CVE-2026-6222?
CVE-2026-6222 is caused by a missing authorization check for the 'forminator_action' parameter in the Forminator Forms plugin.
Who is affected by CVE-2026-6222?
CVE-2026-6222 affects all installations of the Forminator Forms plugin for WordPress that are version 1.51.1 or lower.
What types of data could be exposed due to CVE-2026-6222?
CVE-2026-6222 could expose sensitive information submitted through forms, which can be accessed without proper authorization.