WordPress Plugin Vulnerabilities
Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import
Description
The plugin does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who submits it. The same user is refused an identical form through both the ordinary form editor and the ordinary form import.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
PRIVESC
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-18 (about 2 days ago)
Added
2026-09-18 (about 1 day ago)
Last Updated
2026-09-18 (about 1 day ago)