Missing Authorization Vulnerability in Calculated Fields Form by Codepeople
CVE-2026-25368
6.5MEDIUM
What is CVE-2026-25368?
The Calculated Fields Form plugin by Codepeople has a missing authorization vulnerability that allows attackers to exploit incorrectly configured access control security levels. This can enable unauthorized access to sensitive information and actions within the plugin, particularly impacting versions from n/a up to and including 5.4.4.1. Users are advised to ensure proper access controls and update to secure versions to mitigate this risk.
Affected Version(s)
Calculated Fields Form 0 <= 5.4.4.1