PT-2026-79513 · WordPress · Forminator Forms

CVE-2026-19222

·

Published

2026-08-22

·

Updated

2026-08-23

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Forminator Forms versions prior to 1.57.0.7
Description The plugin fails to consistently enforce role restrictions on registration forms. This allows users with permissions to create forms to configure a registration form that assigns the administrator role to any visitor who registers through it, leading to authenticated privilege escalation.
Recommendations Update Forminator Forms to version 1.57.0.7 or later.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19222

Affected Products

Forminator Forms