Authorization Bypass Vulnerability in Advanced Form Integration Plugin for WordPress
CVE-2026-16587

4.3MEDIUM

What is CVE-2026-16587?

The Advanced Form Integration β€” Connect Forms to 200+ Apps plugin for WordPress is susceptible to an authorization bypass flaw. This vulnerability arises from a failure to adequately verify user permissions, allowing authenticated users with at least subscriber access to manipulate stored MailUp OAuth tokens. Consequently, these users can replace legitimate tokens with malicious ones, effectively taking control of future form submissions directed to the compromised MailUp account. Any logged-in user who can access the /wp-admin/profile.php page is at risk, highlighting the necessity for proper authorization checks in the plugin's code to prevent unauthorized data access and manipulation.

Affected Version(s)

Advanced Form Integration β€” Connect Forms to 200+ Apps 0 <= 2.6.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.