Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104797— Advanced Form Integration <= 2.9.0 - Unauthenticated Unverified Password Change to Authentication Bypass / Privilege Escalation via Contact Form 7 Submission to Ultimate Member Update Profile Field Action

Quick assessment

Affected
nasirahmed Advanced Form Integration — Connect Forms to 300+ Apps
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件 Advanced Form Integration — Connect Forms to 300+ Apps 存在身份验证绕过漏洞,影响版本为 2.9.0 及之前所有版本。 该漏洞源于插件中的 函数,该函数用于处理 Ultimate Member 插件的“更新个人资料字段”操作。攻击者可利用此函数,通过提供目标用户的电子邮件地址解析出对应的 WordPress 用户,并将攻击者可控的字段键(field key)和字段值直接传递给 函数,且在 上下文中执行。该上下文明确绕过了 Ultimat

CVSS 8.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104797

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Advanced Form Integration <= 2.9.0 - Unauthenticated Unverified Password Change to Authentication Bypass / Privilege Escalation via Contact Form 7 Submission to Ultimate Member Update Profile Field Action
Source: CVE Program / CVE List V5
Vulnerability Description
The Advanced Form Integration — Connect Forms to 300+ Apps plugin for WordPress is vulnerable to Authentication Bypass via Unverified Password Change in all versions up to, and including, 2.9.0 The `adfoin_ultimatememberac_send_data` function, which powers the Ultimate Member "Update Profile Field" action, resolves the target WordPress user from an attacker-supplied email address and passes an attacker-controlled field key and value directly to `UM()->user()->update_profile()` in the `account` context — which explicitly bypasses Ultimate Member's banned-key validation — without performing any submitter identity verification, ownership check, capability check, current-password reauthentication, or restriction on sensitive keys such as `user_pass`. This makes it possible for unauthenticated attackers to change the password of any WordPress user account, including Administrator accounts, by submitting a public Contact Form 7 form with a target email and `user_pass` as the field key, enabling full site takeover. Exploitation requires an administrator to have pre-configured a Contact Form 7 integration that maps the target email, field key, and value from public form inputs to the Ultimate Member Update Profile Field action — the exact workflow the plugin's own UI advertises for this action type.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nasirahmed Advanced Form Integration — Connect Forms to 300+ Apps 0 ~ 2.9.0 -

II. Public POCs for CVE-2026-104797

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104797

请登录查看更多情报信息。

Other References for CVE-2026-104797 (6)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104797

No comments yet


Leave a comment