CVE-2026-87069: Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripe
The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and that construction happens on every wp-admin request for any logged-in user. Any authenticated user, including a Subscriber with no permissions in the Forminator Forms WordPress plugin before 1.57.2.1, can therefore rewrite the saved field configuration of any form on the site, including a live payment form.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Forminator Forms WordPress pluginto a version that resolves this vulnerability.Fixed in 1.57.2.1
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user can exploit it, including a Subscriber account with no Forminator-specific permissions. The affected migration runs during wp-admin requests for every logged-in user.
What can an attacker change?
An attacker can rewrite the saved field configuration of any form on the site, including live payment forms. The issue affects the one-time Stripe payment-field migration.
Does exploitation require access to Forminator administration features?
No. The migration lacks nonce, capability, and ownership checks, so a logged-in user does not need Forminator permissions or ownership of the targeted form.
How can I determine whether my site is affected?
Check whether the installed Forminator Forms version is earlier than 1.57.2.1. Sites in that version range with authenticated WordPress users are exposed.