Description
The Advanced Form Integration — Connect Forms to 300+ Apps plugin for WordPress is vulnerable to Authentication Bypass via Unverified Password Change in all versions up to, and including, 2.9.0 The `adfoin_ultimatememberac_send_data` function, which powers the Ultimate Member "Update Profile Field" action, resolves the target WordPress user from an attacker-supplied email address and passes an attacker-controlled field key and value directly to `UM()->user()->update_profile()` in the `account` context — which explicitly bypasses Ultimate Member's banned-key validation — without performing any submitter identity verification, ownership check, capability check, current-password reauthentication, or restriction on sensitive keys such as `user_pass`. This makes it possible for unauthenticated attackers to change the password of any WordPress user account, including Administrator accounts, by submitting a public Contact Form 7 form with a target email and `user_pass` as the field key, enabling full site takeover. Exploitation requires an administrator to have pre-configured a Contact Form 7 integration that maps the target email, field key, and value from public form inputs to the Ultimate Member Update Profile Field action — the exact workflow the plugin's own UI advertises for this action type.
Published: 2026-10-10
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Authentication bypass allowing password reset of any WordPress user, including administrators.
Action: Immediate Patch
AI Analysis

Impact

The Advanced Form Integration plug‑in for WordPress contains a flaw that lets attackers bypass authentication by using an unauthenticated Contact Form 7 submission. When the plugin’s Ultimate Member Update Profile Field action is used, the function adfoin_ultimatememberac_send_data takes an attacker‑supplied email and field key/value pair, resolves the target WordPress user from the email, and passes the pair directly to UM()->user()->update_profile() with no validation. If the field key is 'user_pass', the attacker can change that user’s password. Because the plugin does not check the submitter’s identity, ownership, or current password, an unauthenticated attacker can change the password of any user account, giving full control of the site.

Affected Systems

The vulnerability affects the Advanced Form Integration plug‑in for WordPress, version 2.9.0 and earlier. The flaw manifests when an administrator has set up a Contact Form 7 integration that maps public form fields to the Ultimate Member Update Profile Field action.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. A password reset that allows full site takeover is possible even without authentication. The EPSS score is not available, but because the attack requires only a public form that has been configured by an administrator, the potential for exploitation is non‑negligible. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known exploits yet, but the attack vector is straightforward and the bypass is complete.

Generated by OpenCVE AI on October 10, 2026 at 04:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Advanced Form Integration plug‑in to the latest version (2.10.0 or later) to remove the vulnerable logic.
  • Disable or remove any Contact Form 7 integration that maps to the Ultimate Member Update Profile Field action until the plugin is patched.
  • If immediate upgrade is not possible, reconfigure the form to exclude the 'user_pass' field key or restrict the action to authenticated users only.

Generated by OpenCVE AI on October 10, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description The Advanced Form Integration — Connect Forms to 300+ Apps plugin for WordPress is vulnerable to Authentication Bypass via Unverified Password Change in all versions up to, and including, 2.9.0 The `adfoin_ultimatememberac_send_data` function, which powers the Ultimate Member "Update Profile Field" action, resolves the target WordPress user from an attacker-supplied email address and passes an attacker-controlled field key and value directly to `UM()->user()->update_profile()` in the `account` context — which explicitly bypasses Ultimate Member's banned-key validation — without performing any submitter identity verification, ownership check, capability check, current-password reauthentication, or restriction on sensitive keys such as `user_pass`. This makes it possible for unauthenticated attackers to change the password of any WordPress user account, including Administrator accounts, by submitting a public Contact Form 7 form with a target email and `user_pass` as the field key, enabling full site takeover. Exploitation requires an administrator to have pre-configured a Contact Form 7 integration that maps the target email, field key, and value from public form inputs to the Ultimate Member Update Profile Field action — the exact workflow the plugin's own UI advertises for this action type.
Title Advanced Form Integration <= 2.9.0 - Unauthenticated Unverified Password Change to Authentication Bypass / Privilege Escalation via Contact Form 7 Submission to Ultimate Member Update Profile Field Action
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T03:26:44.569Z

Reserved: 2026-10-02T13:11:58.643Z

Link: CVE-2026-104797

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T04:18:08.677

Modified: 2026-10-10T04:18:08.677

Link: CVE-2026-104797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T04:30:17Z

Weaknesses