Executive brief
Online Contact Widget is a WordPress plugin that allows websites to display a contact form. An unauthenticated attacker can bypass access controls to view or modify data they should not have permission to access, potentially exposing sensitive user information or allowing unauthorized actions on affected websites.
Technical details
This vulnerability is a broken access control flaw in the Online Contact Widget WordPress plugin affecting versions 1.3.0 and earlier. The vulnerability allows unauthenticated attackers to bypass authorization checks, gaining unauthorized access to pages or functionality that should be restricted. No authentication is required to exploit this vulnerability, making it easily accessible over the network. An attacker can access sensitive data or perform unauthorized actions through the affected plugin. As of the advisory date, no official patch is available; mitigation via security plugins is recommended as a temporary measure.
Affected products
- Online Contact Widget Contributors Online Contact Widget <=1.3.0
Timeline
- 2026-08-18: disclosed: Vulnerability published by Patchstack
- 2026-08-18: advisory: CVE-2026-32472 assigned