Junglewise Threat Intelligence

CVE-2026-59534: Aurovrata Venet Post My CF7 Form broken access control

CVE-2026-59534 · Severity: high · CVSS 7.5 · Published 2026-07-27

Executive brief

Aurovrata Venet Post My CF7 Form, a WordPress plugin used to map Contact Form 7 submissions to custom post types, contains a security flaw that allows unauthorized users to perform restricted actions. An unauthenticated attacker could exploit this to modify website content or settings without permission. This could lead to unauthorized data modification and potential disruption of website operations.

Technical details

A broken access control vulnerability exists in the Post My CF7 Form plugin for WordPress due to missing authorization checks (CWE-862) in certain functions. The flaw allows an unauthenticated remote attacker to execute actions that should be restricted to higher-privileged users. According to the CVSS vector, the attack is low complexity and requires no user interaction, primarily impacting the integrity of the system. The vulnerability is addressed in version 7.0.0.

Affected products

  • Aurovrata Venet Post My CF7 Form <= 6.2.0

Timeline

  • 2026-05-16: other: Reported by researcher Mitchell
  • 2026-07-23: advisory: Patchstack advisory published
  • 2026-07-27: disclosed: NVD publication date

References