Back to overview

CVE-2026-5229

CRITICAL
9.8
CVSS 3.1
Description
The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which WordPress account to authenticate after a LINE OAuth login. When LINE doesn't provide an email address (which is common), the plugin falls back to reading the 'form_notify_line_email' cookie value without verifying that the LINE account is associated with that email address. This makes it possible for unauthenticated attackers to gain access to any user account on the site, including administrator accounts, by completing a LINE OAuth flow with their own LINE account while injecting a malicious cookie containing the target victim's email address.

Metadata

CVE ID
CVE-2026-5229
State
PUBLISHED
Assigner
Wordfence
Reserved
2026-03-31 13:24 UTC
Published
2026-05-15 07:46 UTC
Last updated
2026-05-15 13:27 UTC
Primary CWE
CWE-287
CWE-287 Improper Authentication
Vendor / Product
m615926 / Receive Notifications After Form Submitting – Form Notify for Any Forms
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
m615926 Receive Notifications After Form Submitting – Form Notify for Any Forms 0 ≤ 1.1.10
Weakness (CWE)
CWESourceDescription
CWE-287 cna CWE-287 Improper Authentication
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview