Impact
The Forminator Forms WordPress plugin prior to version 1.57.1 fails to check whether network site registration is enabled before allowing site signup. An attacker who is not authenticated can trigger this flaw to create a new site on the multisite network and automatically receive administrator privileges on that site. This grants the attacker full control over content, users, and settings for the newly created site.
Affected Systems
WordPress installations running the Forminator Forms plugin with a version earlier than 1.57.1 on a multisite network. The vulnerable module is present in the plugin behavior that handles new site registration, regardless of the network's site‑creation settings.
Risk and Exploitability
The vulnerability is exploitable by any unauthenticated web user through a crafted HTTP request to the plugin’s site‑signup endpoint. The CVSS score is 3.7, indicating a low to moderate severity, but the impact remains serious because the attacker gains administrator rights on a newly created site, which can be used to launch further attacks within the multisite network. The EPSS score is less than 1%, the vulnerability is not listed in CISA KEV, and the lack of a verification check creates a clear path to privilege escalation.
OpenCVE Enrichment