PT-2026-65399 · WordPress · Advanced Form Integration

·

CVE-2026-16587

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Advanced Form Integration — Connect Forms to 200+ Apps versions prior to 2.6.1
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated users with subscriber-level access or higher can exploit this by accessing the /wp-admin/profile.php endpoint. This occurs because the admin init hook executes for all logged-in users visiting any page within the wp-admin directory. An attacker can use the auth redirect() function to overwrite the adfoin mailup keys option with malicious OAuth tokens, allowing them to hijack form-submission data sent to a MailUp account under their control or nullify the tokens to disable the integration.
Recommendations Update to a version newer than 2.6.0.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16587

Affected Products

Advanced Form Integration