Impact
The Forminator Forms plugin for WordPress fails to enforce role validation when a registration form is nested inside an imported quiz. This flaw allows a user who may import quizzes to publish a live form that grants any role—including administrator—to anyone who submits that form. As a result, an attacker can create a public form that automatically upgrades arbitrary users to privileged roles, enabling unauthorized access to administrative capabilities.
Affected Systems
WordPress users running the Forminator Forms plugin version earlier than 1.57.2.1 are affected. The vulnerability arises when a registration form is embedded within a quiz that is imported, and the plugin then publishes that form publicly.
Risk and Exploitability
Exploitation requires an authenticated user with the ability to import quizzes, making the attack vector an authenticated upload. The missing role check can immediately elevate any form submitter to a high‑privilege role. The CVSS score of 6.6 reflects a medium severity risk, and the EPSS score of < 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Due to the impact of gaining administrative access, this vulnerability should be treated with elevated urgency.
OpenCVE Enrichment