PatchSiren

registrationformbuilder CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM registrationformbuilder CVE published 2026-05-22

CVE-2026-8692

The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to authorization bypass. This issue, affecting versions up to and including 1.1.1, allows authenticated attackers with subscriber-level access or higher to modify form structures by writing to the plugin's FORMS database table. The 'ajax-nonce' used by this handler is publicly accessible v [truncated]