SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-19222

MEDIUM · CVSS 6.6 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Forminator Forms plugin for WordPress prior to version 1.57.0.7 has a vulnerability that fails to consistently enforce role restrictions on registration forms, potentially allowing unauthorized users to assign themselves the administrator role. This could lead to a complete compromise of the WordPress site, making it critical for site administrators using this plugin to update to the latest version immediately to mitigate the risk. WordPress administrators and security teams should prioritize this update to prevent unauthorized access and maintain site integrity.

CVE
CVE-2026-19222
Severity
MEDIUM
CVSS
6.6
EPSS
0.26%
WordPress

Original NVD Description

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.