CVE-2026-6214General

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_for_saving_export_schedule() function in library/class-export.php failing to perform a capability check before saving the scheduled export configuration, unlike the parallel listen_for_csv_export() function which correctly verifies user permissions. This makes it possible for authenticated attackers with subscriber-level access to configure a scheduled export job that emails all form submissions to an attacker-controlled email address, resulting in sensitive data exfiltration.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-07); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-07: 2Mentions · 2026-05-08: 1Technical Details · 2026-05-07: 105-0705-08
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-072
Disclosure1General1
2026-05-081
General1
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-6214 📊 Severity: 6.5 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6214 #CVE-2026-6214 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/G7RMoFlhuD

    Post summary

    The tweet announces a new medium‑severity CVE affecting WordPress (CVE‑2026‑6214) and provides a link to the NVD entry, but offers no additional technical, exploit, or mitigation details.

    0000057
    156 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6214 The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_for_saving_export_sch… https://www.cve.org/CVERecord?id=CVE-2026-6214

    Post summary

    This text announces CVE-2026-6214, a missing authorization flaw in WordPress Forminator Forms plugin for versions up to 1.53.0.

    00000104
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6214 Missing Authorization in Forminator Forms Plugin for WordPress Up ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6214 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post merely announces CVE‑2026‑6214 and links to a vulnerability detail page, offering no proof‑of‑concept, exploit code, active usage evidence, patch information, or technical specifics.

    0000054
    4.0K followersView on X

Explore more