The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
Metrics
Affected Vendors & Products
References
History
Sun, 23 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Sun, 23 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | |
| Metrics |
cvssV3_1
|
Sat, 22 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Sat, 22 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it. | |
| Title | Forminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registration Form Role Bypass | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-08-22T06:00:17.071Z
Updated: 2026-08-23T15:33:41.708Z
Reserved: 2026-08-07T09:04:29.255Z
Link: CVE-2026-19222
Updated: 2026-08-23T15:24:41.383Z
Status : Deferred
Published: 2026-08-22T06:16:16.383
Modified: 2026-08-26T16:30:52.723
Link: CVE-2026-19222
No data.