Description
Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data.

This issue affects FormLayer: from n/a through 1.0.6.
Published: 2026-07-05
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Insertion of Sensitive Information Into Sent Data flaw that allows an attacker to retrieve embedded sensitive data from form submissions. The flaw results in accidental disclosure of confidential information that should not be exposed, potentially compromising user privacy and data integrity.

Affected Systems

The Softaculous FormLayer plugin for WordPress, all releases up to and including version 1.0.6, is affected. Versions 1.0.7 and newer have the fix and are not impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote exploitation via accessible web forms, as the plugin processes user‑submitted data and sends it to external destinations.

Generated by OpenCVE AI on July 23, 2026 at 15:38 UTC.

Remediation

Vendor Solution

Update the WordPress FormLayer Plugin to the latest available version (at least 1.0.7).


OpenCVE Recommended Actions

  • Update the WordPress FormLayer plugin to version 1.0.7 or later.
  • Remove or mask any sensitive data from form fields and confirmation emails to prevent accidental exposure.
  • Ensure that only authorized administrators can modify form settings and view submission data by tightening access controls.

Generated by OpenCVE AI on July 23, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 05 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6.
Title WordPress FormLayer plugin <= 1.0.6 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-07T02:53:38.126Z

Reserved: 2026-07-05T21:27:29.081Z

Link: CVE-2026-59519

cve-icon Vulnrichment

Updated: 2026-07-07T02:53:34.155Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T15:45:02Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data