Impact
The vulnerability exists in the Forminator Forms WordPress plugin prior to version 1.57.0.7. Users who have the capability to create forms can manipulate a registration form so that any visitor who registers through it is granted the administrator role. The weakness lies in inconsistent enforcement of role restrictions, allowing a privileged user to elevate a visitor's permissions to the highest level, effectively giving full administrative access to the entire WordPress installation. This attack can compromise confidentiality, integrity, and availability of site data and functions.
Affected Systems
Affected systems include WordPress sites that have the Forminator Forms plugin installed at a version earlier than 1.57.0.7. The issue is specific to the plugin's registration form feature, and any site configuration that permits form creation by non‑administrator users with that capability is vulnerable.
Risk and Exploitability
The CVSS score of 6.6 indicates medium severity, and the EPSS score of < 1% reflects a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely exploit path involves a user with form‑creation rights creating a registration form that assigns the administrator role to new registrants. Visitors who register through this form are granted administrator privileges, allowing the attacker to obtain full administrative control over the WordPress installation without needing additional access privileges.
OpenCVE Enrichment