Authorization Bypass Vulnerability in Advanced Form Integration Plugin for WordPress
CVE-2026-16587
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-16587?
The Advanced Form Integration β Connect Forms to 200+ Apps plugin for WordPress is susceptible to an authorization bypass flaw. This vulnerability arises from a failure to adequately verify user permissions, allowing authenticated users with at least subscriber access to manipulate stored MailUp OAuth tokens. Consequently, these users can replace legitimate tokens with malicious ones, effectively taking control of future form submissions directed to the compromised MailUp account. Any logged-in user who can access the /wp-admin/profile.php page is at risk, highlighting the necessity for proper authorization checks in the plugin's code to prevent unauthorized data access and manipulation.
Affected Version(s)
Advanced Form Integration β Connect Forms to 200+ Apps 0 <= 2.6.0