Junglewise Threat Intelligence

CVE-2026-27393: Tobias CF7 WOW Styler missing authorization in access control

CVE-2026-27393 · Severity: medium · CVSS 5.3 · Published 2026-05-21

Executive brief

CF7 WOW Styler is a WordPress plugin used to customize the appearance of Contact Form 7 forms. A security flaw in the plugin allows unauthorized individuals to bypass access controls and potentially modify settings or perform actions intended only for administrators. This could lead to unauthorized changes to the website's form styles or configuration, though it does not directly expose sensitive customer data.

Technical details

The CF7 WOW Styler plugin for WordPress is vulnerable to a Broken Access Control (Missing Authorization) vulnerability in versions up to and including 1.7.6. The flaw stems from a failure to implement proper authorization checks or nonce validation on certain functions, allowing unauthenticated attackers to execute actions that should be restricted to higher-privileged users. An attacker can exploit this over the network without any user interaction. The vulnerability is classified as CWE-862 (Missing Authorization). A patch is available in version 1.8.5.

Affected products

  • Tobias CF7 WOW Styler <= 1.7.6

Timeline

  • 2025-11-14: other: Reported by Rapid0nion
  • 2026-05-21: disclosed: Early warning sent to Patchstack customers
  • 2026-05-21: advisory: Published by Patchstack and NVD
  • 2026-05-21: patched: Patch available in version 1.8.5

References