PatchSiren cyber security CVE debrief
CVE-2026-104797 nasirahmed CVE debrief
The Advanced Form Integration plugin for WordPress is vulnerable to authentication bypass via unverified password change in versions up to and including 2.9.0. This allows unauthenticated attackers to change the password of any WordPress user account, including Administrator accounts, by submitting a public Contact Form 7 form with a target email and user_pass as the field key.
- Vendor
- nasirahmed
- Product
- Advanced Form Integration — Connect Forms to 300+ Apps
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
WordPress administrators and users of the Advanced Form Integration plugin should assess their exposure and take immediate action to update the plugin and restrict access to the Contact Form 7 plugin. Security teams should monitor for suspicious activity and consider implementing additional security measures.
Why it matters
CVE-2026-104797 is a high-severity vulnerability in the Advanced Form Integration plugin for WordPress, allowing unauthenticated attackers to change user passwords and potentially take over the site. Defenders should immediately update the plugin, restrict Contact Form 7 access, and monitor for suspicious activity.
- Unauthenticated attackers can change the password of any WordPress user account, including Administrator accounts.
- This vulnerability can lead to full site takeover if exploited.
- Defenders should verify the plugin version and restrict public submissions to the Contact Form 7 plugin.
- Remediation priority is high due to the potential for site takeover.
Technical summary
The Advanced Form Integration plugin for WordPress has a vulnerability that allows unauthenticated attackers to change the password of any WordPress user account. This is achieved through the adfoin_ultimatememberac_send_data function, which is used in the Ultimate Member 'Update Profile Field' action. The function does not perform necessary checks, allowing attackers to submit a public Contact Form 7 form with a target email and user_pass as the field key, effectively bypassing authentication.
Defensive priority
High
Recommended defensive actions
- Immediately update the Advanced Form Integration plugin to a version beyond 2.9.0.
- Restrict access to the Contact Form 7 plugin to prevent public submissions.
- Monitor user account changes and investigate any suspicious password change attempts.
- Consider implementing additional security measures such as two-factor authentication.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability exists in the adfoin_ultimatememberac_send_data function, which powers the Ultimate Member 'Update Profile Field' action. This function resolves the target WordPress user from an attacker-supplied email address and passes an attacker-controlled field key and value directly to UM()->user()->update_profile() without performing any submitter identity verification, ownership check, capability check, current-password reauthentication, or restriction on sensitive keys such as user_pass.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104797 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104797
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104797 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104797
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Advanced Form Integration <= 2.9.0 - Unauthenticated Unverified Password Change to Authenticatio
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104797.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.9.0/platforms/ultimatememberac/ultimatememberac.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.9.0/includes/triggers/cf7/cf7.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/advanced-form-integration/
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.