Executive brief
A security vulnerability exists in CformsII, a WordPress plugin used for creating and managing contact forms. This flaw allows an attacker to trick a logged-in administrator into performing unintended actions on the website without their consent. Such an attack could lead to unauthorized changes in plugin settings or a disruption of the form services, potentially impacting site operations and user communication.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the bgermann CformsII plugin for WordPress through version 15.1.3. The vulnerability stems from a lack of proper nonce validation or equivalent CSRF protections on sensitive administrative actions. An unauthenticated remote attacker can exploit this by inducing a site administrator to visit a malicious link or submit a crafted web form while authenticated. Successful exploitation can allow the attacker to modify plugin configurations or cause a denial of service (high availability impact) by altering form data, though it typically does not result in direct data exfiltration.
Affected products
- bgermann CformsII n/a through 15.1.3
Timeline
- 2026-05-25: disclosed
- 2026-05-25: advisory