Description
Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.
Published: 2026-06-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Advanced Form Integration plugin for WordPress, in versions up to 1.126.12, suffers from a broken access control flaw that allows users with insufficient privileges to read or modify subscriber data. The vulnerability arises because the plugin fails to enforce proper authorization checks on subscriber endpoints, resulting in a security weakness classified as CWE-862. As a consequence, an attacker who can interact with the plugin via the web interface may gain unauthorized access to personal subscriber information, potentially compromising privacy and data integrity.

Affected Systems

WordPress sites that have installed the Advanced Form Integration plugin at version 1.126.12 or earlier. The vulnerability affects all environments where the plugin is active, regardless of the specific hosting configuration, as the plugin code is executed within the WordPress core environment.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate to high severity, while the EPSS score of less than 1% suggests that the likelihood of an exploit occurring in the wild is currently very low. The vulnerability is not listed in CISA’s KEV catalog, implying it has not been observed as part of known exploitation campaigns as of this assessment. Based on the description, the attack vector is inferred to be remote via the web interface; an attacker must be able to access the vulnerable plugin’s endpoints, typically by authenticating as a user with any role. Once authenticated, the lack of proper authorization checks allows the attacker to read or modify subscriber data.

Generated by OpenCVE AI on June 16, 2026 at 20:30 UTC.

Remediation

Vendor Solution

Update the WordPress Advanced Form Integration Plugin to the latest available version (at least 1.127.0).


OpenCVE Recommended Actions

  • Upgrade the Advanced Form Integration plugin to version 1.127.0 or later
  • Review and remove any custom code that accesses subscriber data without role verification
  • Configure WordPress capabilities to ensure the subscriber role has only the permissions explicitly required by your site

Generated by OpenCVE AI on June 16, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Nasirahmed
Nasirahmed advanced Form Integration
Wordpress
Wordpress wordpress
Vendors & Products Nasirahmed
Nasirahmed advanced Form Integration
Wordpress
Wordpress wordpress

Tue, 16 Jun 2026 06:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.
Title WordPress Advanced Form Integration plugin <= 1.126.12 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Nasirahmed Advanced Form Integration
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-16T01:25:25.181Z

Reserved: 2026-04-29T09:04:47.837Z

Link: CVE-2026-42659

cve-icon Vulnrichment

Updated: 2026-06-16T01:25:20.112Z

cve-icon NVD

Status : Deferred

Published: 2026-06-15T21:16:55.573

Modified: 2026-06-15T21:24:32.790

Link: CVE-2026-42659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T20:45:02Z

Weaknesses