Description
The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
Published: 2026-08-22
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via role bypass in form registration
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the Forminator Forms WordPress plugin prior to version 1.57.0.7. Users who have the capability to create forms can manipulate a registration form so that any visitor who registers through it is granted the administrator role. The weakness lies in inconsistent enforcement of role restrictions, allowing a privileged user to elevate a visitor's permissions to the highest level, effectively giving full administrative access to the entire WordPress installation. This attack can compromise confidentiality, integrity, and availability of site data and functions.

Affected Systems

Affected systems include WordPress sites that have the Forminator Forms plugin installed at a version earlier than 1.57.0.7. The issue is specific to the plugin's registration form feature, and any site configuration that permits form creation by non‑administrator users with that capability is vulnerable.

Risk and Exploitability

The CVSS score of 6.6 indicates medium severity, and the EPSS score of < 1% reflects a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely exploit path involves a user with form‑creation rights creating a registration form that assigns the administrator role to new registrants. Visitors who register through this form are granted administrator privileges, allowing the attacker to obtain full administrative control over the WordPress installation without needing additional access privileges.

Generated by OpenCVE AI on August 23, 2026 at 19:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Forminator Forms to version 1.57.0.7 or later to ensure role restrictions are correctly enforced.
  • Review all registration forms on your site and remove any that grant the administrator role to new registrants.
  • Disable role assignment capabilities in existing forms until the plugin is upgraded.
  • Limit form creation rights to users with legitimate administrative or developer responsibilities, preventing privileged form building by unauthorized users.

Generated by OpenCVE AI on August 23, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 23 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 23 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 22 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 22 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
Title Forminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registration Form Role Bypass
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-23T15:33:41.708Z

Reserved: 2026-08-07T09:04:29.255Z

Link: CVE-2026-19222

cve-icon Vulnrichment

Updated: 2026-08-23T15:24:41.383Z

cve-icon NVD

Status : Deferred

Published: 2026-08-22T06:16:16.383

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-19222

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-23T19:30:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management