Impact
The vulnerability resides in the WordPress Forminator plugin versions 1.56.0 and earlier, permitting a user with Contributor access to increase their privileges. The flaw stems from inadequate privilege checks, enabling the elevation of rights to admin level. This confirms a CWE‑266 weakness in privilege management, leading to unauthorized access and potential control over the website.
Affected Systems
The affected product is the Forminator plugin by WPMU DEV. All installations running version 1.56.0 or older are vulnerable and must be upgraded to 1.56.0.1 or newer.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the web interface; an attacker needs an existing Contributor account to exploit the flaw and then trigger the privilege escalation, turning the user into an administrator.
OpenCVE Enrichment