<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Advanced Form Integration — Connect Forms to 300+ Apps (&lt;= 2.9.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/advanced-form-integration--connect-forms-to-300+-apps--2.9.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 05:34:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/advanced-form-integration--connect-forms-to-300+-apps--2.9.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in Advanced Form Integration WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-wordpress-afi-bypass/</link><pubDate>Sat, 10 Oct 2026 05:34:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-wordpress-afi-bypass/</guid><description>CVE-2026-104797 allows unauthenticated attackers to change the passwords of any WordPress user, including administrators, via an unverified profile update action in the Advanced Form Integration plugin.</description><content:encoded><![CDATA[<p>The Advanced Form Integration - Connect Forms to 300+ Apps plugin for WordPress (versions 2.9.0 and below) contains a critical authentication bypass vulnerability, identified as CVE-2026-104797. The flaw exists within the <code>adfoin_ultimatememberac_send_data</code> function, which is designed to process Ultimate Member &quot;Update Profile Field&quot; actions. The function fails to perform necessary identity verification, ownership checks, or capability checks before updating user profile data. Furthermore, it explicitly bypasses banned-key validation, allowing users to modify sensitive keys, including <code>user_pass</code>.</p>
<p>Defenders should note that exploitation is contingent upon a specific configuration: an administrator must have set up a Contact Form 7 integration that maps public form inputs (email, field key, and value) to the Ultimate Member Update Profile Field action. When this condition is met, an unauthenticated attacker can supply a target user's email address and the <code>user_pass</code> key to reset that user's password, granting the attacker full administrative access to the WordPress site.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to hijack any user account on the affected WordPress site. Because the vulnerability permits the modification of the <code>user_pass</code> field, an attacker can target administrative accounts to gain full site control, perform unauthorized data exfiltration, install persistent backdoors, or distribute malicious content through the site.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the Advanced Form Integration plugin to version 2.9.1 or later immediately.</li>
<li>Review all configured Contact Form 7 integrations for the Advanced Form Integration plugin to ensure they do not map user-supplied input to sensitive WordPress profile fields, specifically <code>user_pass</code>.</li>
<li>Audit WordPress user accounts and administrative logs for unauthorized password changes or suspicious profile modifications occurring since the initial deployment of the plugin.</li>
<li>Disable the &quot;Update Profile Field&quot; action in the Advanced Form Integration plugin until the patch is applied.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>authentication-bypass</category><category>cve-2026-104797</category></item></channel></rss>