MEDIUM
registrationformbuilder
CVE published 2026-05-22
CVE-2026-8692
The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to authorization bypass. This issue, affecting versions up to and including 1.1.1, allows authenticated attackers with subscriber-level access or higher to modify form structures by writing to the plugin's FORMS database table. The 'ajax-nonce' used by this handler is publicly accessible v [truncated]