NONE · 0

CVE-2026-19222

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure...

Vulnerability Description

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.

References

FAQ

What is CVE-2026-19222?

CVE-2026-19222 is a documented vulnerability. The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure...

How severe is CVE-2026-19222?

CVSS scoring is not yet available for CVE-2026-19222. Check NVD for updates.

Is there a patch for CVE-2026-19222?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.