Impact
The vulnerability arises because the plugin does not verify user authorization when setting integration credentials. An authenticated attacker with subscriber-level or higher access can overwrite the adfoin_mailup_keys option with arbitrary token data. This action lets the attacker redirect future form submissions to a MailUp account they control or break the integration by nullifying the token. The weakness is documented as "Authorization Bypass Through User-Controlled Key."
Affected Systems
WordPress sites running the Advanced Form Integration plugin version 2.6.0 or earlier, including any prior releases of this plugin. The vendor is nasirahmed:"Advanced Form Integration — Connect Forms to 200+ Apps".
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact, but the EPSS score of less than 1% shows a low probability of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires only that an attacker be logged in to the WordPress admin area and can access /wp-admin/profile.php, a route that fires admin_init for all logged‑in users. Once accessed, the attacker can send the overwrite request and affect the site's integration with MailUp.
OpenCVE Enrichment