CVE-2026-11794
The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when
CVSS
8.1
High
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Published: Jul 1, 2026 · Last modified: Jul 1, 2026
0.2%EPSS · 30 days0.4%
2026-08-222026-09-19
The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public form field. This requires a specific, non-default multi-Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 configuration.
No related CVEs by CWE or product.