← Back

CVE-2026-1753

nvd nist
Published: Mar 11, 2026Modified: Apr 15, 2026Deferred

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
Exploitability: 2.3 / Impact: 4.0
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).

Timeline (4)

3/11/2026
4 changes
CVE Modified - CWE
02:16 PM
- -
+ CWE-639
CVE Modified - CVSS V3.1
02:16 PM
- -
+ AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
New CVE Received - Reference
06:17 AM
- -
+ https://wpscan.com/vulnerability/c42dbab9-b729-4748-88e5-0bd2f6d66e3d/
New CVE Received - Description
06:17 AM
- -
+ The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).