Description
The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who submits it. The same user is refused an identical form through both the ordinary form editor and the ordinary form import.
Published: 2026-09-20
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

The Forminator Forms plugin for WordPress fails to enforce role validation when a registration form is nested inside an imported quiz. This flaw allows a user who may import quizzes to publish a live form that grants any role—including administrator—to anyone who submits that form. As a result, an attacker can create a public form that automatically upgrades arbitrary users to privileged roles, enabling unauthorized access to administrative capabilities.

Affected Systems

WordPress users running the Forminator Forms plugin version earlier than 1.57.2.1 are affected. The vulnerability arises when a registration form is embedded within a quiz that is imported, and the plugin then publishes that form publicly.

Risk and Exploitability

Exploitation requires an authenticated user with the ability to import quizzes, making the attack vector an authenticated upload. The missing role check can immediately elevate any form submitter to a high‑privilege role. The CVSS score of 6.6 reflects a medium severity risk, and the EPSS score of < 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Due to the impact of gaining administrative access, this vulnerability should be treated with elevated urgency.

Generated by OpenCVE AI on September 20, 2026 at 17:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Forminator Forms to version 1.57.2.1 or later.
  • Restrict the ability to import quizzes to users with administrative rights only.
  • Review any publicly published forms that were imported via quizzes and revoke or modify any that grant elevated roles.

Generated by OpenCVE AI on September 20, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions forminator Forms
Vendors & Products Wordpress-extensions
Wordpress-extensions forminator Forms

Sun, 20 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-285

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who submits it. The same user is refused an identical form through both the ordinary form editor and the ordinary form import.
Title Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import
References

Subscriptions

Wordpress-extensions Forminator Forms
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-20T13:50:02.901Z

Reserved: 2026-09-08T19:02:31.821Z

Link: CVE-2026-87068

cve-icon Vulnrichment

Updated: 2026-09-20T13:49:44.973Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T07:16:50.643

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-87068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:48:39Z

Weaknesses
  • CWE-269

    Improper Privilege Management