PT-2026-67010 · WordPress · Gutena Forms

·

CVE-2026-11995

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder versions prior to 1.9.1
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Unauthenticated attackers can modify the read/unread status of or permanently trash arbitrary form submission entries for any form. This occurs because the nonce (a unique token used to prevent cross-site request forgery) issued by the check ajax referer() function is emitted to unauthenticated visitors via wp localize script() on any public page containing a Gutena Forms block, allowing anonymous attackers to obtain it easily.
Recommendations Update Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder to version 1.9.1 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11995

Affected Products

Gutena Forms