Impact
The Advanced Form Integration plug‑in for WordPress contains a flaw that lets attackers bypass authentication by using an unauthenticated Contact Form 7 submission. When the plugin’s Ultimate Member Update Profile Field action is used, the function adfoin_ultimatememberac_send_data takes an attacker‑supplied email and field key/value pair, resolves the target WordPress user from the email, and passes the pair directly to UM()->user()->update_profile() with no validation. If the field key is 'user_pass', the attacker can change that user’s password. Because the plugin does not check the submitter’s identity, ownership, or current password, an unauthenticated attacker can change the password of any user account, giving full control of the site.
Affected Systems
The vulnerability affects the Advanced Form Integration plug‑in for WordPress, version 2.9.0 and earlier. The flaw manifests when an administrator has set up a Contact Form 7 integration that maps public form fields to the Ultimate Member Update Profile Field action.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. A password reset that allows full site takeover is possible even without authentication. The EPSS score is not available, but because the attack requires only a public form that has been configured by an administrator, the potential for exploitation is non‑negligible. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known exploits yet, but the attack vector is straightforward and the bypass is complete.
OpenCVE Enrichment