PT-2026-84624 · WordPress · Formlayer
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FormLayer WordPress plugin versions prior to 1.0.9
Description
An authorization bypass exists in the public submission handler that allows unauthenticated users to retrieve the full stored configuration of a form. This can lead to the disclosure of sensitive information, such as notification recipient addresses, confirmation redirect targets, and integration settings, including data from forms that have not been published.
Recommendations
Update FormLayer WordPress plugin to version 1.0.9 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Formlayer