PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104797 nasirahmed CVE debrief

The Advanced Form Integration plugin for WordPress is vulnerable to authentication bypass via unverified password change in versions up to and including 2.9.0. This allows unauthenticated attackers to change the password of any WordPress user account, including Administrator accounts, by submitting a public Contact Form 7 form with a target email and user_pass as the field key.

Vendor
nasirahmed
Product
Advanced Form Integration — Connect Forms to 300+ Apps
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

WordPress administrators and users of the Advanced Form Integration plugin should assess their exposure and take immediate action to update the plugin and restrict access to the Contact Form 7 plugin. Security teams should monitor for suspicious activity and consider implementing additional security measures.

Why it matters

CVE-2026-104797 is a high-severity vulnerability in the Advanced Form Integration plugin for WordPress, allowing unauthenticated attackers to change user passwords and potentially take over the site. Defenders should immediately update the plugin, restrict Contact Form 7 access, and monitor for suspicious activity.

  • Unauthenticated attackers can change the password of any WordPress user account, including Administrator accounts.
  • This vulnerability can lead to full site takeover if exploited.
  • Defenders should verify the plugin version and restrict public submissions to the Contact Form 7 plugin.
  • Remediation priority is high due to the potential for site takeover.

Technical summary

The Advanced Form Integration plugin for WordPress has a vulnerability that allows unauthenticated attackers to change the password of any WordPress user account. This is achieved through the adfoin_ultimatememberac_send_data function, which is used in the Ultimate Member 'Update Profile Field' action. The function does not perform necessary checks, allowing attackers to submit a public Contact Form 7 form with a target email and user_pass as the field key, effectively bypassing authentication.

Defensive priority

High

Recommended defensive actions

  • Immediately update the Advanced Form Integration plugin to a version beyond 2.9.0.
  • Restrict access to the Contact Form 7 plugin to prevent public submissions.
  • Monitor user account changes and investigate any suspicious password change attempts.
  • Consider implementing additional security measures such as two-factor authentication.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability exists in the adfoin_ultimatememberac_send_data function, which powers the Ultimate Member 'Update Profile Field' action. This function resolves the target WordPress user from an attacker-supplied email address and passes an attacker-controlled field key and value directly to UM()->user()->update_profile() without performing any submitter identity verification, ownership check, capability check, current-password reauthentication, or restriction on sensitive keys such as user_pass.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104797 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104797

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104797 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104797

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Advanced Form Integration <= 2.9.0 - Unauthenticated Unverified Password Change to Authenticatio

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104797.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.9.0/platforms/ultimatememberac/ultimatememberac.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.9.0/includes/triggers/cf7/cf7.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/advanced-form-integration/

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.