CVE-2026-19222

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-22 06:16

Updated : 2026-08-26 16:30


NVD link : CVE-2026-19222

Mitre link : CVE-2026-19222

CVE.ORG link : CVE-2026-19222


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management