Executive brief
Formie, a popular form-building plugin for Craft CMS, contains a security flaw where administrative settings were not properly protected. This allows users who have limited access to the plugin to bypass restrictions and modify global configuration settings or access import/export tools. An attacker with a low-privileged account could use this to tamper with form workflows or disrupt website operations.
Technical details
A missing authorization vulnerability (CWE-862) exists in Formie's administrative settings routes. In affected versions, the server side did not consistently enforce the 'formie-accessSettings' permission for specific control panel routes, such as /admin/formie/settings and /admin/formie/settings/import-export. An authenticated Craft CMS control panel user with minimal Formie access can bypass intended restrictions to view or modify global plugin settings. The vulnerability is resolved in version 3.1.28 by enforcing the required permission across all settings controllers and actions.
Affected products
- Verbb Formie < 3.1.28
Timeline
- 2026-06-05: disclosed: Initial disclosure to vendor
- 2026-06-05: patched: Version 3.1.28 released
- 2026-07-17: advisory: GitHub Advisory published
References
- https://api.github.com/users/chaitanyagarware
- https://github.com/chaitanyagarware
- https://api.github.com/users/chaitanyagarware/gists%7B/gist_id%7D
- https://api.github.com/users/chaitanyagarware/repos
- https://avatars.githubusercontent.com/u/97582002?v=4
- https://api.github.com/users/chaitanyagarware/events%7B/privacy%7D