Executive brief
Forminator Forms is a WordPress form-builder plugin used on multisite installations. A flaw in how the plugin handles network-wide settings allows a single-site administrator to gain control over the entire WordPress network by installing and executing malicious code across all sites without needing network-level privileges or credentials.
Technical details
The vulnerability is a privilege escalation and arbitrary code execution flaw stemming from insufficient authorization checks on network-wide settings. A single-site administrator can exploit this by: (1) extracting a callback nonce from the plugin's hub connection screen, (2) setting a network-wide API key credential via an unauthenticated parameter, (3) using that credential to invoke a remote command channel (authenticated via HMAC-SHA256) that accepts plugin installation and activation requests, and (4) uploading and executing arbitrary PHP code across the entire network. The attack requires the plugin to be network-activated (the default for the free version) and the attacker to hold admin privileges on at least one site within the multisite network. No fix information beyond patching to version 1.57.0.5 or later is currently available.
Affected products
- WPMUDEV Forminator Forms before 1.57.0.5
Timeline
- 2026-08-20: disclosed
- 2026-08-22: advisory
- 2026-08-22: patched: Fixed in version 1.57.0.5