Executive brief
Advanced Forms is a WordPress plugin used to create and manage complex forms on websites. A security flaw in the plugin's access control settings allows unauthorized individuals to perform actions that should be restricted to administrators. This could lead to unauthorized changes to site content or form configurations, potentially disrupting business operations or compromising site integrity.
Technical details
A Broken Access Control vulnerability (CWE-862: Missing Authorization) exists in the Phil Kurth Advanced Forms plugin for WordPress. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing sensitive functions. An unauthenticated remote attacker can exploit this to perform high-privilege actions without valid credentials. The vulnerability is addressed in version 1.9.3.8.
Affected products
- Phil Kurth Advanced Forms <= 1.9.3.7
Timeline
- 2026-05-05: disclosed: Reported by Jakub Herman
- 2026-07-07: advisory: Patchstack advisory published
- 2026-07-13: advisory: NVD published CVE-2026-57378
- patched: Fixed in version 1.9.3.8