MEDIUM
outlawgt
CVE published 2026-09-05
CVE-2026-75018
The Custom Contact Forms plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 7.16. This allows authenticated attackers with contributor-level access and above to permanently force-delete arbitrary posts of any post type and write arbitrary post meta. The vulnerability is due to improper verification of user authorization in the Custom Contact Forms plugin. Th [truncated]