WordPress Plugin Vulnerabilities
Forminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registration Form Role Bypass
Description
The plugin does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
PRIVESC
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Thanh Lam Tang
Submitter
Thanh Lam Tang
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-20 (about 2 days ago)
Added
2026-08-20 (about 1 day ago)
Last Updated
2026-08-21 (about 8 hours ago)