Executive brief
The Tectite Forms plugin for WordPress, which is used to manage forms on websites, contains a security flaw that allows unauthorized changes to its settings. By tricking a site administrator into clicking a malicious link, an attacker can remotely modify plugin configurations. This could lead to unauthorized changes in how forms behave or appear on the website, potentially impacting site operations.
Technical details
The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the admin_init function. This vulnerability affects all versions up to and including 1.3. An unauthenticated attacker can exploit this by inducing a logged-in administrator to visit a malicious URL or submit a crafted form. Successful exploitation allows the attacker to modify the plugin's settings, specifically the 'tectite_forms_button' option, which could lead to unauthorized configuration changes on the affected WordPress site.
Affected products
- Tectite Tectite Forms up to, and including, 1.3
Timeline
- 2026-06-02: disclosed: Initial publication of the CVE record.
- 2026-06-02: advisory: Wordfence published the vulnerability details.
References
- https://plugins.trac.wordpress.org/browser/tectite-forms/tags/1.3/php/class-tectite-forms.php
- https://plugins.trac.wordpress.org/browser/tectite-forms/tags/1.3/php/class-tectite-forms.php
- https://plugins.trac.wordpress.org/browser/tectite-forms/tags/1.3/views/admin.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/965b6a19-3e5f-446c-a739-746e886a5585?source=cve