CVE-2026-19222

Summary

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.

Affected Software

VendorProductVersion RangeStatus
UnknownForminator Forms0 < 1.57.0.7affected

Weaknesses

  • CWE-269 Improper Privilege Management

References