Description
The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's stored MailUp OAuth tokens in the adfoin_mailup_keys option with attacker-controlled tokens, hijacking future form-submission data to a MailUp account they control or nulling the tokens to break the integration entirely. This is exploitable by any authenticated user who can reach /wp-admin/profile.php, as admin_init fires for all logged-in users visiting any wp-admin page.
Published: 2026-07-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises because the plugin does not verify user authorization when setting integration credentials. An authenticated attacker with subscriber-level or higher access can overwrite the adfoin_mailup_keys option with arbitrary token data. This action lets the attacker redirect future form submissions to a MailUp account they control or break the integration by nullifying the token. The weakness is documented as "Authorization Bypass Through User-Controlled Key."

Affected Systems

WordPress sites running the Advanced Form Integration plugin version 2.6.0 or earlier, including any prior releases of this plugin. The vendor is nasirahmed:"Advanced Form Integration — Connect Forms to 200+ Apps".

Risk and Exploitability

The CVSS score of 4.3 indicates moderate impact, but the EPSS score of less than 1% shows a low probability of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires only that an attacker be logged in to the WordPress admin area and can access /wp-admin/profile.php, a route that fires admin_init for all logged‑in users. Once accessed, the attacker can send the overwrite request and affect the site's integration with MailUp.

Generated by OpenCVE AI on August 3, 2026 at 15:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Advanced Form Integration plugin to the latest version (≥ 2.6.1) to eliminate the missing authorization check.
  • If an upgrade is not immediately possible, temporarily restrict all subscriber‑level or higher users from accessing /wp-admin/profile.php or remove the capability that grants such access for the duration of the risk.
  • After resolution, verify the integrity of the adfoin_mailup_keys option in the database to ensure no unauthorized tokens remain.

Generated by OpenCVE AI on August 3, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Nasirahmed
Nasirahmed advanced Form Integration — Connect Forms To 200+ Apps
Wordpress
Wordpress wordpress
Vendors & Products Nasirahmed
Nasirahmed advanced Form Integration — Connect Forms To 200+ Apps
Wordpress
Wordpress wordpress

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's stored MailUp OAuth tokens in the adfoin_mailup_keys option with attacker-controlled tokens, hijacking future form-submission data to a MailUp account they control or nulling the tokens to break the integration entirely. This is exploitable by any authenticated user who can reach /wp-admin/profile.php, as admin_init fires for all logged-in users visiting any wp-admin page.
Title Advanced Form Integration <= 2.6.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary MailUp OAuth Token Overwrite via auth_redirect() Function
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Nasirahmed Advanced Form Integration — Connect Forms To 200+ Apps
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-28T14:54:01.926Z

Reserved: 2026-07-22T13:47:06.150Z

Link: CVE-2026-16587

cve-icon Vulnrichment

Updated: 2026-07-28T13:37:48.655Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T07:16:42.130

Modified: 2026-07-28T16:17:32.807

Link: CVE-2026-16587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:45:04Z

Weaknesses