CVE-2026-56069
Deferred Deferred - Pending Action
Unauthenticated IDOR in Toolset Forms <= 2.6.24

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: Patchstack

Description
Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
toolset forms to 2.6.24 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The WordPress Toolset Forms Plugin, versions 2.6.24 and below, contains an Insecure Direct Object References (IDOR) vulnerability. This flaw allows attackers to bypass authorization and authentication mechanisms, enabling them to access sensitive files, folders, or database interactions without proper permissions.

Because the vulnerability is unauthenticated, attackers do not need to log in to exploit it, making it easier to target many websites.

Impact Analysis

This vulnerability can have a high impact as attackers can access sensitive data or resources without authorization. It may lead to unauthorized access to files, folders, or database information.

The vulnerability has a CVSS score of 7.5, indicating high severity, and can be exploited in mass-exploitation campaigns targeting thousands of websites regardless of their traffic or popularity.

Such unauthorized access can disrupt the availability of services or compromise the integrity of data.

Mitigation Strategies

Immediate action is required to mitigate the risk of this vulnerability.

  • Update the WordPress Toolset Forms Plugin to version 2.6.25 or later.
  • If updating is not possible, seek assistance from your hosting provider or web developer.
  • Apply the mitigation rule issued by Patchstack to block attacks until the plugin is updated.
Compliance Impact

The vulnerability allows attackers to bypass authorization and authentication mechanisms, potentially accessing sensitive files, folders, or database interactions without proper permissions.

Such unauthorized access to sensitive data could lead to non-compliance with data protection regulations like GDPR and HIPAA, which require strict controls over access to personal and sensitive information.

Therefore, exploitation of this vulnerability may result in violations of these standards due to the exposure or compromise of protected data.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56069. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart