PatchSiren cyber security CVE debrief
CVE-2026-11995 saadiqbal CVE debrief
The Gutena Forms plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 1.9.0. This allows unauthenticated attackers to modify form submission entries, potentially leading to data tampering. The plugin's vulnerability is attributed to the nonce issued by check_ajax_referer() not functioning as an authorization barrier. Affected product deployments should be confirmed in managed environments, and owners should be assigned for follow-up. The vulnerability class is authorization bypass, and the likely operational impact is data tampering. Source-confidence limits are based on information from Wordfence and NVD.
- Vendor
- saadiqbal
- Product
- Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-01
- Original CVE updated
- 2026-08-01
- Advisory published
- 2026-08-01
- Advisory updated
- 2026-08-01
Who should care
WordPress site administrators using the Gutena Forms plugin, security teams monitoring for potential data tampering, and operators responsible for maintaining the affected systems should be aware of this vulnerability and take necessary actions to protect their installations. They should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Technical summary
The Gutena Forms plugin for WordPress is vulnerable to authorization bypass due to improper verification of user authorization. This allows unauthenticated attackers to modify form submission entries, potentially leading to data tampering. The plugin's vulnerability is attributed to the nonce issued by check_ajax_referer() not functioning as an authorization barrier. The affected product context is the Gutena Forms plugin for WordPress, and the defensive impact is the potential for data tampering.
Defensive priority
Medium priority due to potential for data tampering
Recommended defensive actions
- Inventory and verify Gutena Forms plugin version
- Restrict access to form submission management
- Monitor for suspicious form activity
- Apply vendor patch when available
- Consider compensating controls for form data
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The Gutena Forms plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 1.9.0. Evidence from Wordfence and NVD indicates a vulnerability in the plugin. The affected scope is limited to form submission entries, and defenders should verify their installations for potential data tampering. Limited details are available on the vendor's remediation plan.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-11995 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-11995
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-11995 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-11995
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.7.1/gutena-forms.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.7.1/includes/admin/class-manage-store.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.7.1/includes/admin/class-manage-store.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.7.1/includes/admin/class-manage-store.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.7.1/includes/admin/class-store.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.9.0/gutena-forms.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/gutena-forms/tags/1.9.0/includes/admin/class-manage-store.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.