Sceawere

Vulnerability Detail

CVE-2026-19222UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Forminator Forms Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.6
Creation Date
1d ago
Vendor
Unknown
Product
Forminator Forms
Attack Type
CWE-269 Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.6",
  "pubDate": "2026-08-22T06:16:16.383Z",
  "pubdate": "2026-08-22T06:16:16.383Z",
  "executiveSummary": "An improper authorization vulnerability exists in the Forminator Forms WordPress plugin before version 1.57.0.7, resulting in a severe privilege escalation risk.\nThe vulnerability manifests through inconsistent enforcement of role restrictions applied to registration forms.\nAn authenticated user with form-building capabilities can leverage this authorization flaw to maliciously configure a registration form.\nThis misconfiguration allows any arbitrary external visitor who registers through the targeted form to be automatically assigned the high-privileged administrator role upon account creation.\nThe primary impact of successful exploitation is full site compromise, as attackers obtain administrative control over the underlying WordPress installation.\nExploitation requires the attacker to possess existing permissions to build forms within the application, or alternatively, to socially engineer or collaborate with a low-privileged form builder.\nThe risk implications are critical due to the immediate elevation of unprivileged users to the highest privilege tier within the content management system.\nOrganizations utilizing affected versions of the Forminator Forms plugin must prioritize remediation to prevent unauthorized privilege assignments.",
  "technicalDetails": "The root cause of the vulnerability stems from inadequate server-side validation and inconsistent role restriction enforcement within the Forminator Forms plugin registration logic.\nSpecifically, the component responsible for processing user registrations fails to properly validate whether the user configuring the form possesses the requisite administrative authorization to assign elevated roles such as administrator.\nWhile role assignment restrictions are ostensibly enforced in the administrative user interface, the underlying processing backend does not consistently verify these constraints against the privileges of the form creator.\nAffected versions include all instances of the Forminator Forms WordPress plugin prior to version 1.57.0.7.\nThe attack flow proceeds as follows: First, an attacker with form-building capabilities navigates to the Forminator Forms interface within the WordPress dashboard. Second, the attacker creates or modifies a registration form, explicitly mapping the post-registration user role parameter to the administrator tier. Third, the attacker publishes or deploys the form to a public-facing page accessible by unauthenticated visitors. Fourth, an arbitrary external visitor accesses the registration form and completes the sign-up process. Fifth, upon submission, the vulnerable plugin backend processes the request and provisions a new user account with the administrator role, bypassing standard access control checks.\nAuthentication is required at the form-building phase, meaning the actor must possess capabilities sufficient to create or edit forms. However, the subsequent exploitation phase requires no authentication, allowing any public visitor to trigger the privilege escalation payload.\nThe network exposure includes the web application interface and any public-facing HTTP/HTTPS endpoints hosting the vulnerable registration forms.\nThe post-exploitation impact includes full administrative compromise of the WordPress site, enabling the execution of arbitrary code, installation of malicious plugins, data exfiltration, and complete control over the hosting environment."
}
CVE-2026-19222: Forminator Forms Privilege Escalation Vulnerability (MEDIUM Severity, CVSS: 6.6) - Sceawere