Executive brief
FormyChat is a WordPress plugin used for contact forms and messaging. This vulnerability allows attackers to access pages and perform actions they shouldn't be allowed to, such as viewing other users' data, without requiring any authentication. This could expose sensitive user information and compromise the security of websites using the plugin.
Technical details
The FormyChat WordPress plugin versions up to 2.15.7 contain a broken access control vulnerability that allows unauthenticated attackers to access protected functionality and view unauthorized data. The vulnerability is classified as OWASP A1 (Broken Access Control) and does not require authentication to exploit. An attacker can craft requests to bypass access controls and retrieve sensitive information from affected websites, including data belonging to other users. The vulnerability has been patched in version 2.15.8 and later; administrators should update immediately.
Affected products
- FormyChat FormyChat <=2.15.7
Timeline
- 2026-08-17: disclosed
- 2026-08-18: patched: Version 2.15.8 released