CVE-2026-6222Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method in `Forminator_Admin_Module_Edit_Page` (admin/abstracts/class-admin-module-edit-page.php) dispatching sensitive module-management actions — including export, delete, clone, delete-entries, publish/draft, and bulk variants — after only a nonce check, without ever verifying that the current user holds the `manage_forminator_modules` capability. The nonce used (`forminator_form_request`) is unconditionally embedded in the global `forminatorData` JavaScript object and localized on every Forminator admin page, including Templates and Reports pages accessible to users who explicitly lack module-management permissions. Because `processRequest()` is invoked during the `admin_menu` action hook — which fires before WordPress enforces page-level capability checks — a user whose Forminator role is restricted to Templates or Reports can craft a valid POST request targeting any published module and successfully trigger the vulnerable actions. This makes it possible for authenticated attackers with subscriber-level access (or any custom low-privilege Forminator role) to export the complete internal configuration of arbitrary forms/polls/quizzes (including notification routing, integration credentials, and conditional logic), delete modules, delete all submissions/votes, clone modules, or bulk-change publish/draft status.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-07: 4Technical Details · 2026-05-07: 305-07
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6222 The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method in… https://www.cve.org/CVERecord?id=CVE-2026-6222 ----- Traducción: CVE-2026-6222 El … http://infoflow.cloud`

    Post summary

    The entry announces CVE‑2026‑6222, noting a missing‑authorization vulnerability in Forminator Forms plugin (≤1.51.1), but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000047
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6222 The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method in… https://www.cve.org/CVERecord?id=CVE-2026-6222

    Post summary

    The post identifies a missing authorization flaw in Forminator Forms WP plugin up to version 1.51.1, but provides only basic technical details without evidence of exploitation or mitigation.

    00000126
    57.4K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-6222 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6222 #CVE-2026-6222 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/dNt06tvtZX

    Post summary

    A medium‑severity CVE (CVE‑2026‑6222) affecting WordPress is reported, with reference to the NVD for more details.

    0000035
    152 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6222 Missing Authorization in Forminator Forms Plugin for WordPress Versions Up to 1.51.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6222

    Post summary

    The post announces a missing‑authorization vulnerability in the Forminator Forms plugin (WordPress ≤1.51.1) without mentioning a PoC, exploit, or available patch.

    0000052
    4.0K followersView on X

Explore more