CVE-2026-87068: Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import

Published Sep 20, 2026
·
Updated

The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who submits it. The same user is refused an identical form through both the ordinary form editor and the ordinary form import.

Affected Software

1 affected component
Forminator Forminator Forms (WordPress plugin)<1.57.2.1

Event History

Sep 20, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A user who has permission to import quizzes can exploit it. They can create and publish a quiz containing a nested registration form configured to grant any WordPress role, including administrator.

2

Is the normal registration-form workflow affected?

The described role-validation bypass is specific to registration forms nested inside imported quizzes. The ordinary form editor and ordinary form import reject the identical form configuration.

3

What is the impact after a malicious quiz is published?

The attacker can make the form publicly reachable, allowing anyone who submits it to receive the role configured in the nested registration form. This can include the administrator role.

4

How can I check for possible exploitation?

Review imported quizzes for nested registration forms and identify any that are published and publicly accessible. Pay particular attention to forms configured to assign elevated roles, including administrator.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203