CVE-2026-19222
N/A
N/A
Summary
The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Forminator Forms | 0 < 1.57.0.7 | affected |
Weaknesses
- CWE-269 Improper Privilege Management
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.