CVE-2026-19222

Published: Ago 22, 2026 Last Modified: Ago 22, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.

https://wpscan.com/vulnerability/bb3997c6-4d9a-46f6-85d7-d472dfc00829/