Executive brief
A vulnerability exists in a WordPress plugin used to connect website forms to third-party services like MailUp. An attacker with a basic user account on the site can hijack the connection to MailUp, potentially redirecting form submissions to their own account or disabling the integration entirely. This could lead to the loss of customer leads or disruption of automated marketing workflows.
Technical details
The Advanced Form Integration plugin for WordPress (versions up to 2.6.0) suffers from a missing authorization check (CWE-862) within its MailUp integration logic. The vulnerability is triggered because the plugin executes certain administrative actions during the 'admin_init' hook without verifying the user's capabilities. Since 'admin_init' fires for any logged-in user accessing a dashboard page (such as profile.php), an authenticated attacker with subscriber-level permissions can overwrite the 'adfoin_mailup_keys' option. This allows the attacker to replace legitimate OAuth tokens with their own, enabling them to hijack form data sent to MailUp or break the integration by nulling the tokens.
Affected products
- nasirahmed Advanced Form Integration — Connect Forms to 200+ Apps up to, and including, 2.6.0
Timeline
- 2026-07-28: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.6.0/platforms/mailup/mailup.php
- https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.6.0/platforms/mailup/mailup.php
- https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.6.0/platforms/mailup/mailup.php
- https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.6.0/platforms/mailup/mailup.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3621411%40advanced-form-integration&new=3621411%40advanced-form-integration
- https://www.wordfence.com/threat-intel/vulnerabilities/id/af913bb1-eff6-47cd-9471-f74bafda1e52?source=cve