Authentication Bypass in Advanced Form Integration WordPress Plugin
CVE-2026-104797 allows unauthenticated attackers to change the passwords of any WordPress user, including administrators, via an unverified profile update action in the Advanced Form Integration plugin.
CVE search metadata
CVE search record: CVE-2026-104797. Severity: high. CVSS: 8.1. KEV: no. Product: Advanced Form Integration — Connect Forms to 300+ Apps (<= 2.9.0). Brief: Authentication Bypass in Advanced Form Integration WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wordpress-afi-bypass/
The Advanced Form Integration - Connect Forms to 300+ Apps plugin for WordPress (versions 2.9.0 and below) contains a critical authentication bypass vulnerability, identified as CVE-2026-104797. The flaw exists within the adfoin_ultimatememberac_send_data function, which is designed to process Ultimate Member "Update Profile Field" actions. The function fails to perform necessary identity verification, ownership checks, or capability checks before updating user profile data. Furthermore, it explicitly bypasses banned-key validation, allowing users to modify sensitive keys, including user_pass.
Defenders should note that exploitation is contingent upon a specific configuration: an administrator must have set up a Contact Form 7 integration that maps public form inputs (email, field key, and value) to the Ultimate Member Update Profile Field action. When this condition is met, an unauthenticated attacker can supply a target user's email address and the user_pass key to reset that user's password, granting the attacker full administrative access to the WordPress site.
Impact
Successful exploitation allows unauthenticated attackers to hijack any user account on the affected WordPress site. Because the vulnerability permits the modification of the user_pass field, an attacker can target administrative accounts to gain full site control, perform unauthorized data exfiltration, install persistent backdoors, or distribute malicious content through the site.
Recommendation
- Upgrade the Advanced Form Integration plugin to version 2.9.1 or later immediately.
- Review all configured Contact Form 7 integrations for the Advanced Form Integration plugin to ensure they do not map user-supplied input to sensitive WordPress profile fields, specifically
user_pass. - Audit WordPress user accounts and administrative logs for unauthorized password changes or suspicious profile modifications occurring since the initial deployment of the plugin.
- Disable the "Update Profile Field" action in the Advanced Form Integration plugin until the patch is applied.
Immediate actions
Upgrade Advanced Form Integration to 2.9.1 or later
Mitigations
Disable Update Profile Field action in plugin settings
CVE-2026-104797