Impact
The Forminator plugin implements an incorrect privilege assignment that lets a user with a lower role gain a higher role. This is a classic authorization bypass (CWE-266). If exploited, the attacker can elevate within WordPress, gaining complete control of the site, including the ability to install additional plugins, change site settings, or access sensitive data.
Affected Systems
WPMU DEV Forminator, versions from the earliest available up to and including 1.57.3. Any installation of Forminator 1.57.3 or earlier is affected; newer releases are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. EPSS information is not available, the exploit probability is unknown, and the vulnerability is not listed in CISA KEV. The likely attack vector requires an authenticated user that has at least a non‑admin role; the attacker then uses the plugin’s functionality to change role assignments and elevate privileges. Once higher privileges are obtained, the attacker can perform any action permitted to an administrator.
OpenCVE Enrichment