CVE-2026-1753
6.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
Exploitability: 2.3 / Impact: 4.0
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).
References (1)
Source: contact@wpscan.com
Timeline (4)
3/11/20264 changes
CVE Modified - CWE
02:16 PM
- -
+ CWE-639
CVE Modified - CVSS V3.1
02:16 PM
- -
+ AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
New CVE Received - Reference
06:17 AM
- -
+ https://wpscan.com/vulnerability/c42dbab9-b729-4748-88e5-0bd2f6d66e3d/
New CVE Received - Description
06:17 AM
- -
+ The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).