MEDIUM
HIPAA FORMS
CVE published 2026-09-02
CVE-2026-2688
The HIPAA FORMS WordPress plugin before version 3.2.0 contains a hardcoded authentication bypass parameter used in all AJAX requests. This allows unauthenticated attackers to access protected AJAX endpoints. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Affected users should update the plugin to version 3.2.0 or later and monitor for potential unauthorized access. The CVE [truncated]