Junglewise Threat Intelligence

CVE-2026-42659: Advanced Form Integration broken access control in WordPress plugin

CVE-2026-42659 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Executive brief

The Advanced Form Integration plugin for WordPress, which connects website forms to third-party services, contains a security flaw that allows users with low-level 'Subscriber' accounts to perform actions they should not be authorized to do. This could allow an attacker to modify plugin settings or interfere with form data integrations, potentially disrupting business workflows or data synchronization. A patch is available in version 1.127.0.

Technical details

A broken access control vulnerability (CWE-862) exists in the Advanced Form Integration plugin for WordPress in versions up to and including 1.126.12. The issue stems from missing authorization or nonce checks in certain functions, which allows an authenticated attacker with Subscriber-level privileges to execute higher-privileged actions. While the specific impacted functions are not detailed, the CVSS vector indicates a high impact on integrity (I:H) without impacting confidentiality or availability. The vulnerability is resolved in version 1.127.0.

Affected products

  • Advanced Form Integration Advanced Form Integration <= 1.126.12

Timeline

  • 2026-03-25: other: Vulnerability reported by researcher Idan Vaknin
  • 2026-04-29: disclosed: Initial disclosure by Patchstack
  • 2026-04-29: patched: Version 1.127.0 released to address the issue
  • 2026-06-15: advisory: NVD publication date

References

Related threats