Junglewise Threat Intelligence

CVE-2026-19221: Forminator Forms privilege escalation to network-wide RCE on multisite

CVE-2026-19221 · Severity: high · CVSS 7.2 · Published 2026-08-22

Technologies: WPMUDEV Forminator Forms. Vendors: WPMUDEV.

Executive brief

Forminator Forms is a WordPress form-builder plugin used on multisite installations. A flaw in how the plugin handles network-wide settings allows a single-site administrator to gain control over the entire WordPress network by installing and executing malicious code across all sites without needing network-level privileges or credentials.

Technical details

The vulnerability is a privilege escalation and arbitrary code execution flaw stemming from insufficient authorization checks on network-wide settings. A single-site administrator can exploit this by: (1) extracting a callback nonce from the plugin's hub connection screen, (2) setting a network-wide API key credential via an unauthenticated parameter, (3) using that credential to invoke a remote command channel (authenticated via HMAC-SHA256) that accepts plugin installation and activation requests, and (4) uploading and executing arbitrary PHP code across the entire network. The attack requires the plugin to be network-activated (the default for the free version) and the attacker to hold admin privileges on at least one site within the multisite network. No fix information beyond patching to version 1.57.0.5 or later is currently available.

Affected products

  • WPMUDEV Forminator Forms before 1.57.0.5

Timeline

  • 2026-08-20: disclosed
  • 2026-08-22: advisory
  • 2026-08-22: patched: Fixed in version 1.57.0.5

References

Related threats