Unauthenticated Broken Access Control in FormyChat Plugin by WordPress
CVE-2026-28571
7.5HIGH
What is CVE-2026-28571?
The FormyChat plugin for WordPress is susceptible to an unauthenticated broken access control vulnerability affecting versions 2.15.7 and earlier. This flaw could allow unauthorized users to exploit the system, potentially leading to unauthorized data access. It is crucial for website administrators using this plugin to take proactive measures in securing their sites against this vulnerability.
Affected Version(s)
FormyChat <= 2.15.7