๐Ÿ” CVE Alert

CVE-2026-19220

LOW 3.7

Forminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privilege Escalation

CVSS Score
3.7
EPSS Score
0.2%
EPSS Percentile
5th

The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it.

Vendor unknown
Product forminator forms
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown forminator forms

Be the first to know when new low vulnerabilities affecting unknown forminator forms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Forminator Forms
0 < 1.57.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/99e2a045-15cb-4c58-8090-1f92474f6485/

Credits

Jakub Herman WPScan