Description
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
Published: 2026-08-22
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A privilege escalation flaw in the Forminator Forms WordPress plugin version before 1.57.0.5 allows a site administrator on a multisite network to execute arbitrary code across the entire network. The vulnerability arises because a network‑wide setting is not properly restricted to network administrators, giving an attacker the ability to bypass normal permissions and gain full control of all sites on the multisite installation. This leads to a complete compromise of confidentiality, integrity, and availability for the affected network.

Affected Systems

The vulnerability affects the Forminator Forms plugin for WordPress, specifically any installation running a version earlier than 1.57.0.5 on a multisite network. The consumer is a WordPress site with multisite enabled, where any site administrator can exploit the flaw.

Risk and Exploitability

The CVSS score is not provided, but the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is internal to the network: a site administrator can trigger the exploit through normal plugin interfaces. As the flaw allows arbitrary code execution without additional prerequisites other than administrative rights on a single site, the risk is high for networks with many sites or where site administrators have substantial privileges. Due to the lack of detection metrics, this vulnerability could be overlooked unless active monitoring or immediate patching is performed.

Generated by OpenCVE AI on August 22, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Forminator Forms plugin to version 1.57.0.5 or later.
  • Restrict the network‑wide settings to network administrators only and verify that the setting is not accessible to regular site administrators.
  • If an upgrade is not immediately possible, remove or disable multisite functionality for the affected network to prevent cross‑site privilege escalation.

Generated by OpenCVE AI on August 22, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-77

Sat, 22 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
Title Forminator Forms < 1.57.0.5 - Admin+ Network-Wide RCE via Hub Connector API Key on Multisite
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-22T06:00:16.858Z

Reserved: 2026-08-07T09:04:27.327Z

Link: CVE-2026-19221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T06:16:16.130

Modified: 2026-08-22T06:16:16.130

Link: CVE-2026-19221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T07:30:17Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')