CVE-2026-19220
Forminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privilege Escalation
CVSS Score
3.7
EPSS Score
0.2%
EPSS Percentile
5th
The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it.
| Vendor | unknown |
| Product | forminator forms |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown forminator forms
Be the first to know when new low vulnerabilities affecting unknown forminator forms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Forminator Forms
0 < 1.57.1
References
Credits
Jakub Herman WPScan