Description
The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attackers to delete arbitrary stored form entries by tricking a logged-in administrator into loading a crafted page.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Arbitrary deletion of stored form entries
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a logged‑in administrator to have form entries removed without their consent. By omitting the CSRF nonce, the plugin does not verify the request and it also lacks any capability check, so a crafted page that the admin visits triggers a delete operation on arbitrary entries. The result is loss of data integrity and availability of the form records.

Affected Systems

WordPress sites running the Database Addon for WPForms plugin before version 1.1.1 are affected. The plugin stores form submission records and the vulnerability lies in its entries management module.

Risk and Exploitability

The CVSS score is not listed in the source, but the lack of CSRF protection and missing capability verification give a moderate to high risk for authenticated administrators. An attacker must be able to lure an admin into loading a crafted URL. No public exploits have been reported and the EPSS score is unavailable, but the vulnerability is still exploitable under the described conditions. The plugin is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on October 8, 2026 at 07:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Database Addon for WPForms plugin to version 1.1.1 or later.
  • If an update is not immediately possible, temporarily deactivate the plugin until the patch is applied.
  • Consider adding an additional capability check or CSRF nonce validation to the plugin’s delete action, or switch to a more secure alternative plugin.

Generated by OpenCVE AI on October 8, 2026 at 07:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-352

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attackers to delete arbitrary stored form entries by tricking a logged-in administrator into loading a crafted page.
Title Database Addon For WPForms < 1.1.1 - Arbitrary Form Entry Deletion via CSRF
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:07.643Z

Reserved: 2026-10-04T19:06:50.470Z

Link: CVE-2026-105260

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:41.130

Modified: 2026-10-08T06:16:41.130

Link: CVE-2026-105260

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:45:17Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-352

    Cross-Site Request Forgery (CSRF)