{"id":"CVE-2026-19222","title":"The Forminator Forms  WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator r…","summary":"The Forminator Forms  WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator r…","severity":"none","published":"2026-08-22","updated":"2026-08-22","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19222","references":[{"url":"https://wpscan.com/vulnerability/bb3997c6-4d9a-46f6-85d7-d472dfc00829/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00357,"epssPercentile":0.26682,"ingestedAt":"2026-08-23T04:42:13.104Z","slug":"CVE-2026-19222","body":"## Overview\n\nThe Forminator Forms  WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}