SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19220

LOW · CVSS 3.7 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Forminator Forms plugin for WordPress prior to version 1.57.1 is vulnerable as it fails to verify whether site registration is enabled on a multisite network, allowing unauthenticated users to create new sites and obtain administrator privileges. This could lead to unauthorized access and potential exploitation of the network. WordPress administrators, particularly those using multisite configurations, should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-19220
Severity
LOW
CVSS
3.7
EPSS
0.19%
WordPress

Original NVD Description

The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it.