Sceawere

Vulnerability Detail

CVE-2026-19221UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Forminator Forms Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
1d ago
Vendor
Unknown
Product
Forminator Forms
Attack Type
CWE-94 Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-22T06:16:16.130Z",
  "pubdate": "2026-08-22T06:16:16.130Z",
  "executiveSummary": "A privilege escalation vulnerability exists within the Forminator Forms WordPress plugin before version 1.57.0.5, specifically involving improper access control over network-wide administrative configurations in a WordPress multisite environment.\nThe vulnerability allows an authenticated attacker holding standard administrator privileges on any single, isolated sub-site within a WordPress multisite network to modify global settings intended exclusively for network-wide administrators.\nSuccessful exploitation of this security flaw grants the sub-site administrator the capability to execute arbitrary code across the entire multisite network, leading to complete infrastructure compromise.\nThe root cause stems from a failure to adequately validate and restrict administrative boundaries, permitting localized privilege escalation to a global network scope.\nGiven that an attacker requires existing sub-site administrative privileges to initiate the attack flow, the primary risk involves insider threats, compromised sub-site accounts, or lateral movement within a shared hosting deployment.\nImmediate remediation requires updating the Forminator Forms plugin to version 1.57.0.5 or later, where proper authorization checks are enforced to restrict network-wide settings exclusively to network administrators.",
  "technicalDetails": "The Forminator Forms WordPress plugin before version 1.57.0.5 suffers from an authorization bypass and broken access control vulnerability operating within WordPress multisite network architectures.\nThe vulnerable component resides in the plugin's authorization logic handling administrative options and settings that dictate global execution capabilities.\nIn a standard WordPress multisite installation, administrative roles are segregated into site administrators (managing a single sub-site) and network administrators (super admins managing the entire network).\nThe root cause of the vulnerability is the improper restriction of network-wide settings, failing to verify whether the requesting user possesses super administrator privileges before processing configuration updates.\nPrivilege requirements and authentication necessitate that the malicious actor possesses valid credentials for a sub-site administrator role, granting them access to the plugin's administrative dashboard interface.\nThe attack flow proceeds as follows: First, the authenticated sub-site administrator navigates to the Forminator Forms management interface. Second, the user interacts with configuration parameters or form features designed to persist settings globally across the network. Third, due to the missing authorization validation on the backend endpoint processing these requests, the plugin accepts the configuration changes submitted by the sub-site administrator.\nBy manipulating these network-wide settings, the attacker can leverage plugin features—such as custom code execution vectors, file uploads, or database operations—to inject and execute arbitrary code payloads.\nThe post-exploitation impact spans the entire network, allowing the attacker to compromise all other sub-sites, access sensitive database contents, or achieve remote code execution on the underlying web server hosting the WordPress multisite installation."
}
CVE-2026-19221: Forminator Forms Privilege Escalation Vulnerability (HIGH Severity, CVSS: 7.2) - Sceawere