Unauthorized Access Vulnerability in The Forminator Forms Plugin for WordPress
CVE-2024-10402
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 26 October 2024
What is CVE-2024-10402?
The Forminator Forms plugin for WordPress encompasses a security flaw that allows authenticated users with Contributor-level access or higher to bypass essential capability checks. This vulnerability exists in all versions through 1.35.1, potentially permitting attackers to create, edit, and manipulate forms. Notably, this could lead to unauthorized updates of default registration roles, specifically enabling Users to be assigned as Administrators, posing significant risks to data integrity and user access controls.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Forminator Forms β Contact Form, Payment Form & Custom Form Builder * <= 1.35.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved