PT-2026-95924 · WordPress · Forminator Forms
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Forminator Forms versions prior to 1.57.2.1
Description
An issue exists where role validation is not applied when a registration form is nested within an imported quiz. This allows a user with permissions to import quizzes to publish a publicly accessible form that can grant any user role, including administrator, to anyone who submits the form. This bypasses the restrictions normally enforced by the ordinary form editor and the standard form import process.
Recommendations
Update Forminator Forms to version 1.57.2.1 or later.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forminator Forms