{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aadvanced_form_integrationconnect_forms_to_300_apps/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:advanced_form_integration:connect_forms_to_300_apps:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-104797"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Advanced Form Integration — Connect Forms to 300+ Apps (\u003c= 2.9.0)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","authentication-bypass","cve-2026-104797"],"_cs_type":"advisory","_cs_vendors":["Advanced Form Integration"],"content_html":"\u003cp\u003eThe Advanced Form Integration - Connect Forms to 300+ Apps plugin for WordPress (versions 2.9.0 and below) contains a critical authentication bypass vulnerability, identified as CVE-2026-104797. The flaw exists within the \u003ccode\u003eadfoin_ultimatememberac_send_data\u003c/code\u003e function, which is designed to process Ultimate Member \u0026quot;Update Profile Field\u0026quot; actions. The function fails to perform necessary identity verification, ownership checks, or capability checks before updating user profile data. Furthermore, it explicitly bypasses banned-key validation, allowing users to modify sensitive keys, including \u003ccode\u003euser_pass\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eDefenders should note that exploitation is contingent upon a specific configuration: an administrator must have set up a Contact Form 7 integration that maps public form inputs (email, field key, and value) to the Ultimate Member Update Profile Field action. When this condition is met, an unauthenticated attacker can supply a target user's email address and the \u003ccode\u003euser_pass\u003c/code\u003e key to reset that user's password, granting the attacker full administrative access to the WordPress site.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to hijack any user account on the affected WordPress site. Because the vulnerability permits the modification of the \u003ccode\u003euser_pass\u003c/code\u003e field, an attacker can target administrative accounts to gain full site control, perform unauthorized data exfiltration, install persistent backdoors, or distribute malicious content through the site.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Advanced Form Integration plugin to version 2.9.1 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview all configured Contact Form 7 integrations for the Advanced Form Integration plugin to ensure they do not map user-supplied input to sensitive WordPress profile fields, specifically \u003ccode\u003euser_pass\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user accounts and administrative logs for unauthorized password changes or suspicious profile modifications occurring since the initial deployment of the plugin.\u003c/li\u003e\n\u003cli\u003eDisable the \u0026quot;Update Profile Field\u0026quot; action in the Advanced Form Integration plugin until the patch is applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T05:34:28Z","date_published":"2026-10-10T05:34:28Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wordpress-afi-bypass/","summary":"CVE-2026-104797 allows unauthenticated attackers to change the passwords of any WordPress user, including administrators, via an unverified profile update action in the Advanced Form Integration plugin.","title":"Authentication Bypass in Advanced Form Integration WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-wordpress-afi-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:advanced_form_integration:connect_forms_to_300_apps:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}