Authentication Bypass Vulnerability in Advanced Form Integration Plugin for WordPress
CVE-2026-104797

8.1HIGH

What is CVE-2026-104797?

The Advanced Form Integration plugin for WordPress allows unauthenticated attackers to bypass authentication and change passwords for any user account, including those of administrators. This occurs through the 'adfoin_ultimatememberac_send_data' function, which accepts an attacker-controlled email address and field key, facilitating unauthorized access without any validation checks. Exploitation requires a configuration that directs inputs from the public domain, specifically through a Contact Form 7 form, to the Ultimate Member's profile update functionality, posing significant risk to the security of WordPress sites.

Affected Version(s)

Advanced Form Integration β€” Connect Forms to 300+ Apps 0 <= 2.9.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wachiss
.