Junglewise Threat Intelligence

CVE-2026-11794: Advanced Form Integration privilege escalation in user creation mapping

CVE-2026-11794 · Severity: info · CVSS 8.1 · Published 2026-07-01

Vendors: Unknown.

Executive brief

A vulnerability in a popular WordPress form integration plugin allows unauthenticated visitors to create administrative accounts. By submitting a specially crafted form, an attacker can bypass security restrictions and grant themselves full control over the website. This could lead to complete site takeover, data theft, or the installation of malicious software.

Technical details

The Advanced Form Integration plugin for WordPress (versions before 2.1.1) contains an unauthenticated privilege escalation vulnerability. The root cause is a lack of role validation in the user creation sink when processing form submissions via integrations like WooCommerce or FluentAffiliate. If an administrator has configured an integration to map a public form field (e.g., from Breakdance Form Builder) to the 'Role' or 'User Role' attribute, an attacker can provide the string 'administrator' in that field. The plugin then creates a new user with the specified role without checking against an allowlist. This allows a remote, unauthenticated attacker to gain full administrative access to the WordPress instance. The issue is fixed in version 2.1.1.

Affected products

  • Unknown Advanced Form Integration — Connect Forms to 200+ Apps < 2.1.1

Timeline

  • 2026-06-10: disclosed: Publicly published by WPScan
  • 2026-07-01: advisory: NVD publication date
  • 2026-07-01: patched: Fixed in version 2.1.1

References

Related threats