Description
The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
Published: 2026-08-22
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Forminator Forms WordPress plugin prior to version 1.57.0.7. Users who have the capability to create forms can manipulate a registration form so that any visitor who registers through it is granted the administrator role. The weakness lies in inconsistent enforcement of role restrictions, allowing a privileged user to elevate a visitor's permissions to the highest level, effectively giving full administrative access to the entire WordPress installation. This attack can compromise confidentiality, integrity, and availability of site data and functions.

Affected Systems

Affected systems include WordPress sites that have the Forminator Forms plugin installed at a version earlier than 1.57.0.7. The issue is specific to the plugin's registration form feature, and any site configuration that permits form creation by non‑administrator users with that capability is vulnerable.

Risk and Exploitability

The CVSS score is not provided, but the lack of restriction on role assignment poses a high impact scenario. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV. The likely exploit path involves a legitimate user gaining form‑building rights, then crafting a registration form to assign the administrator role, and finally having a visitor register through that form. The attacker must have form‑creation access but does not need broader system access to succeed.

Generated by OpenCVE AI on August 22, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Forminator Forms to version 1.57.0.7 or later to ensure role restrictions are correctly enforced.
  • Review all registration forms on your site and remove any that grant the administrator role to new registrants.
  • Disable role assignment capabilities in existing forms until the plugin is upgraded.
  • Limit form creation rights to users with legitimate administrative or developer responsibilities, preventing privileged form building by unauthorized users.

Generated by OpenCVE AI on August 22, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 22 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
Title Forminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registration Form Role Bypass
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-22T06:00:17.071Z

Reserved: 2026-08-07T09:04:29.255Z

Link: CVE-2026-19222

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T06:16:16.383

Modified: 2026-08-22T06:16:16.383

Link: CVE-2026-19222

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T07:30:17Z

Weaknesses