Back to overview

CVE-2026-16587

MEDIUM
4.3
CVSS 3.1
Description
The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the site's stored MailUp OAuth tokens in the adfoin_mailup_keys option with attacker-controlled tokens, hijacking future form-submission data to a MailUp account they control or nulling the tokens to break the integration entirely. This is exploitable by any authenticated user who can reach /wp-admin/profile.php, as admin_init fires for all logged-in users visiting any wp-admin page.

Metadata

CVE ID
CVE-2026-16587
State
PUBLISHED
Assigner
Wordfence
Reserved
2026-07-22 13:47 UTC
Published
2026-07-28 05:39 UTC
Last updated
2026-07-28 14:54 UTC
Primary CWE
CWE-862
CWE-862 Missing Authorization
Vendor / Product
nasirahmed / Advanced Form Integration — Connect Forms to 200+ Apps
Sources
cve.org  ·  NVD

Severity & Metrics

4.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
nasirahmed Advanced Form Integration — Connect Forms to 200+ Apps 0 ≤ 2.6.0
Weakness (CWE)
CWESourceDescription
CWE-862 cna CWE-862 Missing Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
4.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Back to overview