Junglewise Threat Intelligence

CVE-2026-56069: Site Building with Toolset Toolset Forms IDOR in cred-frontend-editor

CVE-2026-56069 · Severity: high · CVSS 7.5 · Published 2026-06-26

Executive brief

Toolset Forms is a WordPress plugin used to build front-end forms for content creation and editing. A security flaw allows unauthenticated users to manipulate internal object identifiers, potentially leading to unauthorized access or data modification. This could allow an attacker to interfere with website content or database records without needing a login.

Technical details

The Toolset Forms (cred-frontend-editor) plugin for WordPress contains an Insecure Direct Object Reference (IDOR) vulnerability in versions up to and including 2.6.24. The flaw stems from insufficient validation of user-supplied keys or identifiers, allowing unauthenticated attackers to bypass authorization checks (CWE-639). By manipulating these identifiers in network requests, an attacker can interact with data or objects they are not permitted to access. While the provided CVSS vector indicates an impact on availability, IDOR vulnerabilities typically allow for unauthorized data access or modification. The issue is resolved in version 2.6.25.

Affected products

  • Site Building with Toolset Toolset Forms (cred-frontend-editor) <= 2.6.24

Timeline

  • 2026-06-18: disclosed: Reported by VanTastic
  • 2026-06-25: advisory: Patchstack published advisory
  • 2026-06-26: patched: Version 2.6.25 released

References