CVE-2026-6222
A vulnerability exists in the Forminator Forms plugin for WordPress, affecting versions up to 1.51.1. The issue arises from the plugin's failure to properly authorize user access to sensitive module-management actions, such as exporting and deleting modules, and modifying their status. This is because the plugin relies solely on a nonce check, without verifying the user's capability to perform these actions. As a result, an attacker with subscriber-level access can craft a malicious request to exploit this vulnerability and access sensitive information or perform unauthorized actions.
Based on public CVE data (MITRE/NVD).