Unauthorized Data Modification in Gutena Forms Plugin for WordPress
CVE-2026-1674
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 4 March 2026
What is CVE-2026-1674?
The Gutena Forms plugin for WordPress is exposed to a vulnerability that allows unauthorized modification of data due to insufficient authorization checks within the save_gutena_forms_schema() function. This flaw affects all versions up to 1.6.0 and permits authenticated attackers, with Contributor-level access or higher, to alter option values. Such modifications could lead to erroneous states, impacting legitimate user access, or maliciously enable features like user registration without permission, jeopardizing the website’s integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder * <= 1.6.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved