Unauthenticated Broken Authentication in Gutena Forms by WordPress
CVE-2026-66425

6.5MEDIUM

What is CVE-2026-66425?

The Gutena Forms plugin for WordPress, affecting versions 1.9.0 and earlier, has a vulnerability that allows unauthenticated users to bypass authentication mechanisms. This flaw exposes various functionalities like contact forms, survey forms, feedback forms, and booking forms, potentially leading to unauthorized access and exploitation. Users are encouraged to update to the latest version to mitigate these risks.

Affected Version(s)

Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman | Patchstack Bug Bounty Program
.