Executive brief
Forminator Forms is a WordPress plugin that allows administrators to build custom user registration forms. The plugin fails to properly validate role restrictions, allowing users with form-building permissions to configure a registration form that assigns administrator privileges to any new user who signs up through it. This could allow attackers to gain full administrative control of a WordPress site.
Technical details
The vulnerability is a privilege escalation flaw in the registration form role assignment logic (CWE-269: Improper Access Control). While the builder UI restricts the role dropdown to exclude administrator, the underlying save handler does not validate that the submitted role is in the allowed list. An attacker with create_users capability and form-builder access can replay the form save request with the role-assignment mode set to any value other than "fixed" and the role field set to "administrator", bypassing UI-level restrictions. This requires registration to be enabled on the site and the attacker to hold the create_users capability (typically granted only to administrator roles, but can be assigned to custom roles). The fix was released in version 1.57.0.7.
Affected products
- WPForms Forminator Forms before 1.57.0.7
Timeline
- 2026-08-20: disclosed
- 2026-08-22: patched: Fixed in version 1.57.0.7