
CVE-2026-19221 The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single sit… https://www.cve.org/CVERecord?id=CVE-2026-19221
Post summary
The CVE record outlines a privilege‑escalation flaw in Forminator Forms that lets non‑admin sites influence network settings; no exploitation evidence, PoC, or patch details are provided.

