Junglewise Threat Intelligence

CVE-2026-32472: Online Contact Widget broken access control

CVE-2026-32472 · Severity: high · CVSS 7.5 · Published 2026-08-18

Executive brief

Online Contact Widget is a WordPress plugin that allows websites to display a contact form. An unauthenticated attacker can bypass access controls to view or modify data they should not have permission to access, potentially exposing sensitive user information or allowing unauthorized actions on affected websites.

Technical details

This vulnerability is a broken access control flaw in the Online Contact Widget WordPress plugin affecting versions 1.3.0 and earlier. The vulnerability allows unauthenticated attackers to bypass authorization checks, gaining unauthorized access to pages or functionality that should be restricted. No authentication is required to exploit this vulnerability, making it easily accessible over the network. An attacker can access sensitive data or perform unauthorized actions through the affected plugin. As of the advisory date, no official patch is available; mitigation via security plugins is recommended as a temporary measure.

Affected products

  • Online Contact Widget Contributors Online Contact Widget <=1.3.0

Timeline

  • 2026-08-18: disclosed: Vulnerability published by Patchstack
  • 2026-08-18: advisory: CVE-2026-32472 assigned

References