Skip to main content
Vulnerability Database/CVE-2026-87068

CVE-2026-87068: Forminator Forms WordPress Auth Bypass Flaw

CVE-2026-87068 is an authentication bypass vulnerability in Forminator Forms WordPress plugin that allows unauthorized privilege escalation to administrator role. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-87068 Overview

The Forminator Forms WordPress plugin before version 1.57.2.1 contains a privilege escalation flaw tied to inconsistent role validation. The plugin enforces role restrictions in its standard form editor and standard form import path, but omits the same check when a registration form is nested inside an imported quiz. A user with permission to import quizzes can publish a live, publicly reachable form that assigns any WordPress role, including administrator, to any submitter. The weakness is classified under CWE-269: Improper Privilege Management.

Critical Impact

Any unauthenticated visitor who submits the crafted form receives the role granted by the form, enabling full administrative takeover of the WordPress site.

Affected Products

  • Forminator Forms WordPress plugin, all versions prior to 1.57.2.1
  • WordPress sites permitting quiz imports to non-administrative roles
  • Multisite deployments where sub-site editors can import quizzes

Discovery Timeline

  • 2026-09-20 - CVE-2026-87068 published to the National Vulnerability Database
  • 2026-09-21 - Last updated in NVD database

Technical Details for CVE-2026-87068

Vulnerability Analysis

Forminator Forms supports multiple form types, including registration forms that assign a WordPress role on submission. To prevent trivial privilege escalation, the plugin validates that the user creating or importing a form is authorized to assign the selected role. This validation is applied when a form is created through the standard editor and when a form is imported through the ordinary form import path.

The validation is not applied when a registration form is embedded within an imported quiz. A user authorized to import quizzes can package a registration form as a nested element inside a quiz payload and bypass the role check entirely. The published form is then reachable by any unauthenticated visitor, and submissions trigger role assignment on the target site.

Because the attacker only needs to publish the form once and any visitor can submit it, the impact scales from a single insider action to full site compromise by external actors.

Root Cause

The root cause is inconsistent enforcement of an authorization check across code paths that produce the same artifact. The quiz import handler does not invoke the role validation logic used by the form editor and form importer. This is a classic broken access control pattern in which one entry point trusts the other paths to have performed the check.

Attack Vector

An authenticated user with quiz import privileges crafts a quiz export that contains a nested registration form configured to assign the administrator role. The user imports the quiz through the Forminator quiz import interface. The registration form is published without role validation and made publicly accessible. An attacker submits the form and receives administrator credentials on the target site. The vulnerability requires high privileges to plant, but requires no authentication to exploit once the form is live.

No verified proof-of-concept code has been published. See the WPScan Vulnerability Report for additional technical detail.

Detection Methods for CVE-2026-87068

Indicators of Compromise

  • Unexpected WordPress user accounts with the administrator role created shortly after a Forminator form submission
  • New Forminator forms of type registration published by non-administrator users
  • Quiz import events in the Forminator activity log followed by new published forms
  • Public-facing form URLs on the site that were not authorized by site owners

Detection Strategies

  • Audit the wp_users and wp_usermeta tables for accounts created after 2026-09-20 with elevated capabilities and correlate with Forminator submission logs
  • Inventory all Forminator forms and identify registration forms whose creator is not a site administrator
  • Review web server access logs for POST requests to Forminator form endpoints that precede new user registrations

Monitoring Recommendations

  • Alert on any change to WordPress user roles, particularly promotions to administrator or editor
  • Monitor the Forminator plugin version across managed sites and flag any instance below 1.57.2.1
  • Track quiz import events and require review of any published forms produced by that workflow

How to Mitigate CVE-2026-87068

Immediate Actions Required

  • Update the Forminator Forms plugin to version 1.57.2.1 or later on all WordPress instances
  • Review all existing Forminator registration forms and delete any that were not explicitly authorized
  • Audit WordPress user accounts for unauthorized role assignments and revoke elevated privileges
  • Rotate credentials for any account that may have been created or modified through the vulnerable path

Patch Information

The vendor fixed the issue in Forminator Forms 1.57.2.1 by applying the same role validation used in the form editor and form importer to the quiz import path. Refer to the WPScan Vulnerability Report for advisory details.

Workarounds

  • Restrict the Forminator quiz import capability to administrator accounts only until the patch is applied
  • Disable the Forminator plugin on sites that cannot be updated immediately
  • Require manual review of all newly published forms before they are made publicly reachable
bash
# Verify installed Forminator version via WP-CLI and update if vulnerable
wp plugin get forminator --field=version
wp plugin update forminator --version=1.57.2.1

# List users created after the disclosure date for review
wp user list --role=administrator --fields=ID,user_login,user_registered

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.