Description
The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it.
Published: 2026-08-26
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Forminator Forms WordPress plugin prior to version 1.57.1 fails to check whether network site registration is enabled before allowing site signup. An attacker who is not authenticated can trigger this flaw to create a new site on the multisite network and automatically receive administrator privileges on that site. This grants the attacker full control over content, users, and settings for the newly created site.

Affected Systems

WordPress installations running the Forminator Forms plugin with a version earlier than 1.57.1 on a multisite network. The vulnerable module is present in the plugin behavior that handles new site registration, regardless of the network's site‑creation settings.

Risk and Exploitability

The vulnerability is exploitable by any unauthenticated web user through a crafted HTTP request to the plugin’s site‑signup endpoint. While the CVSS score is not provided, the impact is severe because the attacker gains administrator rights on a freshly created site, which can be used to launch further attacks within the multisite network. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, but the lack of a verification check creates a clear path to privilege escalation.

Generated by OpenCVE AI on August 26, 2026 at 07:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Forminator Forms plugin to version 1.57.1 or later.
  • Disable network site registration in the WordPress multisite settings to prevent new site creation while the plugin is updated.
  • Add a firewall rule or application layer block to deny requests to the plugin’s site‑signup endpoint for unauthenticated users, and monitor site‑creation logs for any unauthorized attempts.

Generated by OpenCVE AI on August 26, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Wed, 26 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it.
Title Forminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privilege Escalation
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-26T14:43:09.681Z

Reserved: 2026-08-07T09:04:25.088Z

Link: CVE-2026-19220

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T07:30:16Z

Weaknesses