CVE-2026-87068: Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import
The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who submits it. The same user is refused an identical form through both the ordinary form editor and the ordinary form import.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A user who has permission to import quizzes can exploit it. They can create and publish a quiz containing a nested registration form configured to grant any WordPress role, including administrator.
Is the normal registration-form workflow affected?
The described role-validation bypass is specific to registration forms nested inside imported quizzes. The ordinary form editor and ordinary form import reject the identical form configuration.
What is the impact after a malicious quiz is published?
The attacker can make the form publicly reachable, allowing anyone who submits it to receive the role configured in the nested registration form. This can include the administrator role.
How can I check for possible exploitation?
Review imported quizzes for nested registration forms and identify any that are published and publicly accessible. Pay particular attention to forms configured to assign elevated roles, including administrator.