SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-19221

HIGH · CVSS 7.2 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Forminator Forms plugin for WordPress prior to version 1.57.0.5 is vulnerable due to inadequate restrictions on a network-wide setting, enabling site administrators within a multisite environment to execute arbitrary code across the entire network. This could lead to significant security breaches, including unauthorized access and control over multiple sites. WordPress multisite administrators should prioritize updating this plugin to mitigate potential exploitation risks.

CVE
CVE-2026-19221
Severity
HIGH
CVSS
7.2
EPSS
0.46%
WordPress

Original NVD Description

The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.