Impact
The Forminator Forms WordPress plugin prior to version 1.57.1 fails to check whether network site registration is enabled before allowing site signup. An attacker who is not authenticated can trigger this flaw to create a new site on the multisite network and automatically receive administrator privileges on that site. This grants the attacker full control over content, users, and settings for the newly created site.
Affected Systems
WordPress installations running the Forminator Forms plugin with a version earlier than 1.57.1 on a multisite network. The vulnerable module is present in the plugin behavior that handles new site registration, regardless of the network's site‑creation settings.
Risk and Exploitability
The vulnerability is exploitable by any unauthenticated web user through a crafted HTTP request to the plugin’s site‑signup endpoint. While the CVSS score is not provided, the impact is severe because the attacker gains administrator rights on a freshly created site, which can be used to launch further attacks within the multisite network. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, but the lack of a verification check creates a clear path to privilege escalation.
OpenCVE Enrichment