Broken Access Control in Ultra Addons for WPForms
CVE-2026-39594

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 June 2026

What is CVE-2026-39594?

The Ultra Addons for WPForms plugin prior to version 1.0.11 is susceptible to broken access control vulnerabilities. This flaw can potentially allow unauthorized users to gain access to sensitive user data or functionality that should only be accessible to authorized subscribers. Organizations using this plugin should apply the necessary updates to secure their applications against potential exploitation.

Affected Version(s)

Ultra Addons for WPForms <= 1.0.11

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cid_Kagenou_Sama | Patchstack Bug Bounty Program
.