CVE-2026-6222: Forminator Forms <= 1.51.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'forminator_action' Parameter

Published May 7, 2026
·
Updated

The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the processRequest() method in ForminatorAdminModuleEditPage (admin/abstracts/class-admin-module-edit-page.php) dispatching sensitive module-management actions — including export, delete, clone, delete-entries, publish/draft, and bulk variants — after only a nonce check, without ever verifying that the current user holds the manageforminatormodules capability. The nonce used (forminatorformrequest) is unconditionally embedded in the global forminatorData JavaScript object and localized on every Forminator admin page, including Templates and Reports pages accessible to users who explicitly lack module-management permissions. Because processRequest() is invoked during the adminmenu action hook — which fires before WordPress enforces page-level capability checks — a user whose Forminator role is restricted to Templates or Reports can craft a valid POST request targeting any published module and successfully trigger the vulnerable actions. This makes it possible for authenticated attackers with subscriber-level access (or any custom low-privilege Forminator role) to export the complete internal configuration of arbitrary forms/polls/quizzes (including notification routing, integration credentials, and conditional logic), delete modules, delete all submissions/votes, clone modules, or bulk-change publish/draft status.

Affected Software

1 affected component
WPMU DEV Forminator Forms<=1.51.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Forminator Forms to a version that resolves this vulnerability.

    Fixed in 1.51.1
  2. Configuration

    In Forminator's processRequest() dispatcher for Forminator_Admin_Module_Edit_Page, add/ensure a capability check for manage_forminator_modules before executing sensitive module-management actions (export, delete, clone, delete-entries, publish/draft, and bulk variants).

    Forminator_Admin_Module_Edit_Page (processRequest) manage_forminator_modules capability check for module-management actions (export, delete, clone, delete-entries, publish/draft, bulk variants) = required
  3. Compensating control

    Restrict access to Forminator module-management admin pages (including Templates and Reports pages where the forminatorData JS object and forminator_form_request nonce are localized) so that only users who have the manage_forminator_modules capability can reach them.

Event History

May 7, 2026
CVE Published
via MITRE·01:25 AM
Data Sourced
via MITRE·01:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-6222?

CVE-2026-6222 has been classified as a medium severity vulnerability due to its potential for unauthorized access to sensitive information.

2

How do I fix CVE-2026-6222?

To mitigate CVE-2026-6222, update the Forminator Forms plugin to version 1.51.2 or later immediately.

3

What causes CVE-2026-6222?

CVE-2026-6222 is caused by a missing authorization check for the 'forminator_action' parameter in the Forminator Forms plugin.

4

Who is affected by CVE-2026-6222?

CVE-2026-6222 affects all installations of the Forminator Forms plugin for WordPress that are version 1.51.1 or lower.

5

What types of data could be exposed due to CVE-2026-6222?

CVE-2026-6222 could expose sensitive information submitted through forms, which can be accessed without proper authorization.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203