Description
The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public form field. This requires a specific, non-default multi-Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 configuration.
Published: 2026-07-01
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Advanced Form Integration – Connect Forms to 200+ Apps plugin fails to enforce role restrictions when creating a WordPress user from a public form submission. An attacker can submit a crafted form that maps a selected field to a user role, creating a new account with administrative privileges. This flaw effectively allows an unauthenticated visitor to gain full control of the site, compromising confidentiality, integrity, and availability. The issue reflects an improper authorization weakness (CWE-284).

Affected Systems

This vulnerability impacts any WordPress installation that has the Advanced Form Integration plugin at a version earlier than 2.1.1. It requires that an active integration maps a role‑setting field to a public form field; if that condition is present, an unauthenticated request can generate an account with the mapped role.

Risk and Exploitability

The CVSS score of 8.1 marks the flaw as high severity, and the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need only to submit a form payload to a public form that is role‑mapped; no authentication or special privileges are required. The resulting privilege escalation would give the attacker full administrative authority over the affected WordPress site.

Generated by OpenCVE AI on July 21, 2026 at 15:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Advanced Form Integration – Connect Forms to 200+ Apps plugin to version 2.1.1 or later.
  • If upgrading is not immediately possible, disable or remove any role mapping that associates a public form field with a user role, ensuring that role assignment is only possible for authenticated users.
  • Review all active integrations to confirm that no public form field is mapped to an administrator role; if such mappings exist, correct or remove them immediately.
  • Inspect the user database for any newly created accounts that possess elevated privileges and remove or re‑evaluate them as necessary.

Generated by OpenCVE AI on July 21, 2026 at 15:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 17 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 15 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 14 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sat, 11 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sat, 11 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Thu, 09 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Thu, 09 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 08 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 07 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Mon, 06 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sun, 05 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Sat, 04 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Fri, 03 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Fri, 03 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 02 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 02 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 02 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 01 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public form field. This requires a specific, non-default multi-Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 configuration.
Title Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-01T10:14:46.721Z

Reserved: 2026-06-09T13:05:09.059Z

Link: CVE-2026-11794

cve-icon Vulnrichment

Updated: 2026-07-01T10:14:43.145Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T15:15:08Z

Weaknesses