{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-104797", "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599", "state": "PUBLISHED", "assignerShortName": "Wordfence", "dateReserved": "2026-10-02T13:11:58.643Z", "datePublished": "2026-10-10T03:26:44.569Z", "dateUpdated": "2026-10-10T03:26:44.569Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599", "shortName": "Wordfence", "dateUpdated": "2026-10-10T03:26:44.569Z" }, "affected": [ { "vendor": "nasirahmed", "product": "Advanced Form Integration — Connect Forms to 300+ Apps", "versions": [ { "version": "0", "status": "affected", "lessThanOrEqual": "2.9.0", "versionType": "semver" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "The Advanced Form Integration — Connect Forms to 300+ Apps plugin for WordPress is vulnerable to Authentication Bypass via Unverified Password Change in all versions up to, and including, 2.9.0 The `adfoin_ultimatememberac_send_data` function, which powers the Ultimate Member \"Update Profile Field\" action, resolves the target WordPress user from an attacker-supplied email address and passes an attacker-controlled field key and value directly to `UM()->user()->update_profile()` in the `account` context — which explicitly bypasses Ultimate Member's banned-key validation — without performing any submitter identity verification, ownership check, capability check, current-password reauthentication, or restriction on sensitive keys such as `user_pass`. This makes it possible for unauthenticated attackers to change the password of any WordPress user account, including Administrator accounts, by submitting a public Contact Form 7 form with a target email and `user_pass` as the field key, enabling full site takeover. Exploitation requires an administrator to have pre-configured a Contact Form 7 integration that maps the target email, field key, and value from public form inputs to the Ultimate Member Update Profile Field action — the exact workflow the plugin's own UI advertises for this action type." } ], "title": "Advanced Form Integration <= 2.9.0 - Unauthenticated Unverified Password Change to Authentication Bypass / Privilege Escalation via Contact Form 7 Submission to Ultimate Member Update Profile Field Action", "references": [ { "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/586fd95e-88c7-4eb8-826c-ae46a11ac21f?source=cve" }, { "url": "https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.9.0/platforms/ultimatememberac/ultimatememberac.php#L169" }, { "url": "https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.9.0/platforms/ultimatememberac/ultimatememberac.php#L83" }, { "url": "https://plugins.trac.wordpress.org/browser/advanced-form-integration/tags/2.9.0/includes/triggers/cf7/cf7.php#L38" }, { "url": "https://plugins.trac.wordpress.org/browser/advanced-form-integration/" }, { "url": "https://plugins.trac.wordpress.org/changeset?reponame=&new=3725787%40advanced-form-integration%2Ftags%2F2.10.0&old=3707004%40advanced-form-integration%2Ftags%2F2.9.0" } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "CWE-287 Improper Authentication", "cweId": "CWE-287", "type": "CWE" } ] } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.1, "baseSeverity": "HIGH" } } ], "credits": [ { "lang": "en", "type": "finder", "value": "wachiss" } ], "timeline": [ { "time": "2026-10-02T13:26:52.000Z", "lang": "en", "value": "Vendor Notified" }, { "time": "2026-10-09T15:05:51.000Z", "lang": "en", "value": "Disclosed" } ] } } }