Description
Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions.
Published: 2026-08-06
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Gutena Forms plugin versions up to 1.9.0 contain an unauthenticated broken authentication flaw that allows an attacker to bypass the plugin’s login controls and gain privileged access. This vulnerability is classified as CWE‑288 and can enable the attacker to view, modify, or delete form configurations, and potentially retrieve sensitive data submitted through the embedded forms.

Affected Systems

WordPress sites that have installed the Gutena Forms plugin by Saad Iqbal, specifically any version 1.9.0 or earlier. All attacks target the plugin’s administrative interface, which is exposed to all visitors of the site.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate risk. Because the flaw permits unauthenticated exploitation via the web interface, the attack vector is remote and does not require the attacker to possess any existing credentials. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified, but the public availability of the plugin and the lack of authentication checks provide a wide attack surface. The vulnerability is not currently listed in the CISA KEV catalog, reducing the visibility to security teams that rely on that feed. Nonetheless, the ease of exploitation and moderate severity warrant prompt remediation.

Generated by OpenCVE AI on August 6, 2026 at 16:11 UTC.

Remediation

Vendor Solution

Update the WordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin to the latest available version (at least 2.0.0).


OpenCVE Recommended Actions

  • Update the Gutena Forms plugin to version 2.0.0 or later to eliminate the authentication bypass flaw.
  • Revoke or change any administrator credentials that were valid during the vulnerable period, ensuring that accounts no longer have unauthorized access.
  • Apply a temporary firewall rule or .htaccess restriction to block unauthenticated access to the plugin’s admin pages until the upgrade is completed.

Generated by OpenCVE AI on August 6, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Saadiqbal
Saadiqbal gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, And Custom Form Builder
Wordpress
Wordpress wordpress
Vendors & Products Saadiqbal
Saadiqbal gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, And Custom Form Builder
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions.
Title WordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication vulnerability
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Saadiqbal Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, And Custom Form Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:48.597Z

Reserved: 2026-07-27T09:00:08.212Z

Link: CVE-2026-66425

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:45:03Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel