CVE-2026-87068 Overview
The Forminator Forms WordPress plugin before version 1.57.2.1 contains a privilege escalation flaw tied to inconsistent role validation. The plugin enforces role restrictions in its standard form editor and standard form import path, but omits the same check when a registration form is nested inside an imported quiz. A user with permission to import quizzes can publish a live, publicly reachable form that assigns any WordPress role, including administrator, to any submitter. The weakness is classified under CWE-269: Improper Privilege Management.
Critical Impact
Any unauthenticated visitor who submits the crafted form receives the role granted by the form, enabling full administrative takeover of the WordPress site.
Affected Products
- Forminator Forms WordPress plugin, all versions prior to 1.57.2.1
- WordPress sites permitting quiz imports to non-administrative roles
- Multisite deployments where sub-site editors can import quizzes
Discovery Timeline
- 2026-09-20 - CVE-2026-87068 published to the National Vulnerability Database
- 2026-09-21 - Last updated in NVD database
Technical Details for CVE-2026-87068
Vulnerability Analysis
Forminator Forms supports multiple form types, including registration forms that assign a WordPress role on submission. To prevent trivial privilege escalation, the plugin validates that the user creating or importing a form is authorized to assign the selected role. This validation is applied when a form is created through the standard editor and when a form is imported through the ordinary form import path.
The validation is not applied when a registration form is embedded within an imported quiz. A user authorized to import quizzes can package a registration form as a nested element inside a quiz payload and bypass the role check entirely. The published form is then reachable by any unauthenticated visitor, and submissions trigger role assignment on the target site.
Because the attacker only needs to publish the form once and any visitor can submit it, the impact scales from a single insider action to full site compromise by external actors.
Root Cause
The root cause is inconsistent enforcement of an authorization check across code paths that produce the same artifact. The quiz import handler does not invoke the role validation logic used by the form editor and form importer. This is a classic broken access control pattern in which one entry point trusts the other paths to have performed the check.
Attack Vector
An authenticated user with quiz import privileges crafts a quiz export that contains a nested registration form configured to assign the administrator role. The user imports the quiz through the Forminator quiz import interface. The registration form is published without role validation and made publicly accessible. An attacker submits the form and receives administrator credentials on the target site. The vulnerability requires high privileges to plant, but requires no authentication to exploit once the form is live.
No verified proof-of-concept code has been published. See the WPScan Vulnerability Report for additional technical detail.
Detection Methods for CVE-2026-87068
Indicators of Compromise
- Unexpected WordPress user accounts with the administrator role created shortly after a Forminator form submission
- New Forminator forms of type registration published by non-administrator users
- Quiz import events in the Forminator activity log followed by new published forms
- Public-facing form URLs on the site that were not authorized by site owners
Detection Strategies
- Audit the wp_users and wp_usermeta tables for accounts created after 2026-09-20 with elevated capabilities and correlate with Forminator submission logs
- Inventory all Forminator forms and identify registration forms whose creator is not a site administrator
- Review web server access logs for POST requests to Forminator form endpoints that precede new user registrations
Monitoring Recommendations
- Alert on any change to WordPress user roles, particularly promotions to administrator or editor
- Monitor the Forminator plugin version across managed sites and flag any instance below 1.57.2.1
- Track quiz import events and require review of any published forms produced by that workflow
How to Mitigate CVE-2026-87068
Immediate Actions Required
- Update the Forminator Forms plugin to version 1.57.2.1 or later on all WordPress instances
- Review all existing Forminator registration forms and delete any that were not explicitly authorized
- Audit WordPress user accounts for unauthorized role assignments and revoke elevated privileges
- Rotate credentials for any account that may have been created or modified through the vulnerable path
Patch Information
The vendor fixed the issue in Forminator Forms 1.57.2.1 by applying the same role validation used in the form editor and form importer to the quiz import path. Refer to the WPScan Vulnerability Report for advisory details.
Workarounds
- Restrict the Forminator quiz import capability to administrator accounts only until the patch is applied
- Disable the Forminator plugin on sites that cannot be updated immediately
- Require manual review of all newly published forms before they are made publicly reachable
# Verify installed Forminator version via WP-CLI and update if vulnerable
wp plugin get forminator --field=version
wp plugin update forminator --version=1.57.2.1
# List users created after the disclosure date for review
wp user list --role=administrator --fields=ID,user_login,user_registered
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
