Description
The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.9.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the read/unread status of or permanently trash arbitrary form submission entries belonging to any form. The nonce issued by check_ajax_referer() does not function as an authorization barrier because the nonce action 'gutena_Forms' is emitted to unauthenticated visitors via wp_localize_script() on any public page that contains a Gutena Forms block, making it freely obtainable by anonymous attackers.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sat, 01 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Saadiqbal
Saadiqbal gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, And Custom Form Builder Wordpress Wordpress wordpress |
|
| Vendors & Products |
Saadiqbal
Saadiqbal gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, And Custom Form Builder Wordpress Wordpress wordpress |
Sat, 01 Aug 2026 08:30:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-01T07:49:49.140Z
Reserved: 2026-06-11T15:15:35.975Z
Link: CVE-2026-11995
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-01T10:30:03Z
Weaknesses
-
CWE-862
Missing Authorization