Sceawere

Vulnerability Detail

CVE-2026-96341UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Forminator Incorrect Privilege Assignment

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
3h ago
Vendor
WPMU DEV
Product
Forminator
Attack Type
Incorrect Privilege Assignment
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

Incorrect Privilege Assignment vulnerability in WPMU DEV Forminator forminator allows Privilege Escalation.This issue affects Forminator: from n/a through 1.57.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-10-10T19:16:59.037Z",
  "pubdate": "2026-10-10T19:16:59.037Z",
  "executiveSummary": "The WPMU DEV Forminator plugin for WordPress is susceptible to an Incorrect Privilege Assignment vulnerability, facilitating unauthorized privilege escalation. This vulnerability affects all versions of the Forminator plugin ranging from n/a through 1.57.3.\nThe flaw stems from improper access control mechanisms within the plugin's internal handling of user or data assignments. By manipulating specific requests, an attacker can elevate their privileges beyond their intended authorization level, potentially gaining administrative or elevated access to the WordPress environment.\nThe primary risk implication is the compromise of site integrity and data confidentiality. An attacker successfully exploiting this vulnerability could execute privileged actions, modify plugin configurations, or perform unauthorized administrative tasks. The exploitation requirements typically involve reaching specific endpoints associated with the plugin’s functionality. Given the nature of privilege escalation, this vulnerability is categorized as high severity due to the potential for complete control over the WordPress application if the escalated account is used to modify system settings or inject malicious content.",
  "technicalDetails": "The vulnerability is classified as an Incorrect Privilege Assignment, occurring when the Forminator plugin fails to adequately validate the authorization context of a request before assigning or modifying user permissions or roles. This security lapse resides within the plugin’s backend processing logic, specifically where user-supplied input influences the assignment of elevated privileges.\nThe exploitation flow typically begins with the attacker identifying the specific request parameters or API hooks that the Forminator plugin uses to process form submissions or administrative actions. By intercepting these requests, the attacker can inject modified parameters that trick the application logic into assigning higher-than-authorized roles to the attacker's user account. The vulnerable component fails to enforce strict server-side permission checks, allowing unauthorized users to invoke functions intended only for administrators or users with elevated roles.\nBecause the plugin logic performs these assignments without verifying the identity or current role of the initiator, an attacker can effectively 'promote' their session. This process does not necessarily require brute force or complex credential theft; rather, it exploits the insecure trust model where the application assumes the input is legitimate. Once the privilege assignment is triggered, the WordPress global user object or internal plugin role-mapping database is updated, granting the attacker persistent elevated access.\nThe impact of this vulnerability is significant in a WordPress environment. Once an attacker gains administrative privileges via this escalation, they can bypass security controls, install or modify malicious plugins, inject arbitrary scripts into pages, or exfiltrate sensitive data stored within the database. The post-exploitation phase often involves the attacker ensuring persistent access, perhaps by creating a backdoored administrative account or modifying site configurations to facilitate further malicious activity. Because this vulnerability is located within the plugin's core request-handling functions, it is accessible via any web-based interaction that reaches the vulnerable code paths, regardless of the attacker’s initial authentication state, provided the specific entry point is publicly reachable."
}
CVE-2026-96341: Forminator Incorrect Privilege Assignment (HIGH Severity, CVSS: 8.2) | Sceawere