Executive brief
A vulnerability in a popular WordPress form integration plugin allows unauthenticated visitors to create administrative accounts. By submitting a specially crafted form, an attacker can bypass security restrictions and grant themselves full control over the website. This could lead to complete site takeover, data theft, or the installation of malicious software.
Technical details
The Advanced Form Integration plugin for WordPress (versions before 2.1.1) contains an unauthenticated privilege escalation vulnerability. The root cause is a lack of role validation in the user creation sink when processing form submissions via integrations like WooCommerce or FluentAffiliate. If an administrator has configured an integration to map a public form field (e.g., from Breakdance Form Builder) to the 'Role' or 'User Role' attribute, an attacker can provide the string 'administrator' in that field. The plugin then creates a new user with the specified role without checking against an allowlist. This allows a remote, unauthenticated attacker to gain full administrative access to the WordPress instance. The issue is fixed in version 2.1.1.
Affected products
- Unknown Advanced Form Integration — Connect Forms to 200+ Apps < 2.1.1
Timeline
- 2026-06-10: disclosed: Publicly published by WPScan
- 2026-07-01: advisory: NVD publication date
- 2026-07-01: patched: Fixed in version 2.1.1