CVE-2026-1753
Received
Received - Intake
Privilege Escalation via Improper Option Validation in Gutena Forms Plugin
Publication date: 2026-03-11
Last updated on: 2026-03-11
Assigner: WPScan
Description
Description
The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gutena | forms | to 1.6.1 (exc) |
| gutena | gutena_forms | to 1.6.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-639 | The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. |