{"id":"CVE-2026-87069","published":"2026-09-23T06:17:04.450","lastModified":"2026-09-23T18:13:31.210","description":"The Forminator Forms  WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and that construction happens on every wp-admin request for any logged-in user. Any authenticated user, including a Subscriber with no permissions in the Forminator Forms  WordPress plugin before 1.57.2.1, can therefore rewrite the saved field configuration of any form on the site, including a live payment form.","cvssScore":3.1,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/cf14469d-eb14-4ab0-acdd-318a6c9d5d92/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}