Junglewise Threat Intelligence

CVE-2026-39594: Themefic Ultra Addons for WPForms broken access control

CVE-2026-39594 · Severity: medium · CVSS 6.4 · Published 2026-06-15

Vendors: Themefic.

Executive brief

Ultra Addons for WPForms is a WordPress plugin that extends the functionality of the WPForms form builder. A security flaw in versions 1.0.11 and earlier allows users with low-level 'Subscriber' accounts to perform actions they should not be authorized to do. This could lead to unauthorized changes to website settings or content, potentially disrupting site operations.

Technical details

The Ultra Addons for WPForms plugin for WordPress (versions <= 1.0.11) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This flaw allows an authenticated attacker with Subscriber-level privileges to execute functions or modify settings that should be restricted to higher-privileged users. The vulnerability is exploitable over the network without user interaction. The issue is resolved in version 1.0.12, which introduces proper authorization validation.

Affected products

  • Themefic Ultra Addons for WPForms <= 1.0.11

Timeline

  • 2026-01-19: other: Reported by researcher Cid_Kagenou_Sama
  • 2026-04-16: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: CVE published to NVD

References