CVE-2026-104797
Received Received - Intake

Authentication Bypass in Advanced Form Integration WordPress Plugin

Vulnerability report for CVE-2026-104797, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The Advanced Form Integration β€” Connect Forms to 300+ Apps plugin for WordPress is vulnerable to Authentication Bypass via Unverified Password Change in all versions up to, and including, 2.9.0 The `adfoin_ultimatememberac_send_data` function, which powers the Ultimate Member "Update Profile Field" action, resolves the target WordPress user from an attacker-supplied email address and passes an attacker-controlled field key and value directly to `UM()->user()->update_profile()` in the `account` context β€” which explicitly bypasses Ultimate Member's banned-key validation β€” without performing any submitter identity verification, ownership check, capability check, current-password reauthentication, or restriction on sensitive keys such as `user_pass`. This makes it possible for unauthenticated attackers to change the password of any WordPress user account, including Administrator accounts, by submitting a public Contact Form 7 form with a target email and `user_pass` as the field key, enabling full site takeover. Exploitation requires an administrator to have pre-configured a Contact Form 7 integration that maps the target email, field key, and value from public form inputs to the Ultimate Member Update Profile Field action β€” the exact workflow the plugin's own UI advertises for this action type.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nasirahmed Advanced Form Integration β€” Connect Forms to 300+ Apps 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass in the Advanced Form Integration plugin for WordPress. It allows unauthenticated attackers to change passwords of any user account, including administrators, by exploiting a flaw in the plugin's integration with Contact Form 7 and Ultimate Member. The issue occurs because the plugin does not verify the identity of the submitter or check ownership before updating user profiles.

Detection Guidance

Check if the Advanced Form Integration β€” Connect Forms to 300+ Apps plugin is installed and if its version is up to 2.9.0. Inspect WordPress user accounts for unauthorized password changes or suspicious profile updates. Review Contact Form 7 integrations configured to map email fields to Ultimate Member actions.

Impact Analysis

If exploited, this vulnerability could allow attackers to take over your WordPress site by changing passwords of administrator accounts. This could lead to complete control over your website, data theft, or further malicious activities such as installing malware or defacing the site.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and access control. Organizations may face legal penalties, reputational damage, and loss of customer trust if such a breach occurs.

Mitigation Strategies

Immediately update the Advanced Form Integration plugin to the latest version beyond 2.9.0. Disable any Contact Form 7 integrations that map to Ultimate Member Update Profile Field actions. Audit WordPress user accounts for unauthorized changes and reset passwords for affected accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104797. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart