Executive brief
Softaculous FormLayer, a WordPress plugin used for creating and managing forms, contains a security flaw that may expose sensitive information. An unauthorized individual could potentially view data that is intended to be hidden or restricted, which could lead to further security compromises. Users are advised to update to version 1.0.7 to resolve this issue.
Technical details
The Softaculous FormLayer plugin for WordPress (versions up to 1.0.6) is vulnerable to CWE-201: Insertion of Sensitive Information Into Sent Data. This flaw allows an unauthenticated remote attacker to retrieve sensitive data that is inadvertently embedded or included in the data sent by the application. The vulnerability is classified as a sensitive data exposure issue with a CVSS 3.1 base score of 5.3. The issue has been addressed in version 1.0.7.
Affected products
- Softaculous FormLayer up to 1.0.6
Timeline
- 2026-06-30: disclosed: Reported by Ananda Dhakal (Patchstack)
- 2026-07-05: advisory: Published by Patchstack and NVD
- 2026-07-05: patched: Version 1.0.7 released to address the issue