CVE-2026-19221: Forminator Forms < 1.57.0.5 - Admin+ Network-Wide RCE via Hub Connector API Key on Multisite
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/forminator-formsto a version that resolves this vulnerability.Fixed in 1.57.0.5
Event History
Frequently Asked Questions
Which WordPress deployments are exposed?
The issue affects WordPress multisite networks using Forminator Forms versions earlier than 1.57.0.5. It involves a network-wide setting, so standalone WordPress sites are not indicated by the available information.
What level of access does an attacker need?
An attacker must already be an administrator of any individual site within the multisite network. Network administrator access is not required.
What is the potential impact after exploitation?
A site-level administrator can execute arbitrary code across the entire multisite network, rather than being limited to the site they administer.
What version remediates the issue?
Upgrade Forminator Forms to version 1.57.0.5 or later.