Privilege Escalation Vulnerability in WPMU DEV Forminator Plugin
CVE-2026-96341

8.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-96341?

A vulnerability exists in the WPMU DEV Forminator plugin that allows unauthorized users to escalate privileges. This issue primarily affects versions of Forminator from n/a through 1.57.3. By exploiting this vulnerability, attackers could perform actions beyond their intended permissions, posing significant risks to the integrity and security of WordPress sites utilizing this plugin. It is crucial for administrators to update their installations to mitigate potential threats.

Affected Version(s)

Forminator 0 <= 1.57.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Elaprendiz1927 | Patchstack Bug Bounty Program
.