Executive brief
A security vulnerability exists in the WPForms plugin for WordPress, which is widely used to create and manage contact forms on websites. An unauthorized person could exploit this flaw to perform actions they should not have permission to do, potentially altering form settings or data. This could lead to unauthorized changes to how the website interacts with visitors or how it handles submitted information.
Technical details
The WPForms plugin (versions 1.10.0.4 and earlier) for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862). A remote, unauthenticated attacker can exploit this vulnerability over the network to execute functions or modify settings that should be restricted to administrative users. The vulnerability stems from a lack of proper validation of user permissions or nonce tokens in certain plugin components. An exploit could allow an attacker to compromise the integrity of the plugin's data or configuration. A patch is available in version 1.10.0.5.
Affected products
- WPForms Contact Form by WPForms <= 1.10.0.4
Timeline
- 2026-03-23: other: Reported by Cyrille COQUARD
- 2026-05-28: patched: Patch released in version 1.10.0.5
- 2026-05-28: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date