Authentication Bypass Vulnerability in Advanced Form Integration Plugin for WordPress
CVE-2026-104797
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-104797?
The Advanced Form Integration plugin for WordPress allows unauthenticated attackers to bypass authentication and change passwords for any user account, including those of administrators. This occurs through the 'adfoin_ultimatememberac_send_data' function, which accepts an attacker-controlled email address and field key, facilitating unauthorized access without any validation checks. Exploitation requires a configuration that directs inputs from the public domain, specifically through a Contact Form 7 form, to the Ultimate Member's profile update functionality, posing significant risk to the security of WordPress sites.
Affected Version(s)
Advanced Form Integration β Connect Forms to 300+ Apps 0 <= 2.9.0