HIGH
nasirahmed
CVE published 2026-10-10
CVE-2026-104797
The Advanced Form Integration plugin for WordPress is vulnerable to authentication bypass via unverified password change in versions up to and including 2.9.0. This allows unauthenticated attackers to change the password of any WordPress user account, including Administrator accounts, by submitting a public Contact Form 7 form with a target email and user_pass as the field key.