ZeroHour

CVE-2026-1753

CVSS 3.1
6.8 medium
EPSS
<1%p10
Published
()
Modified
Description

The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).

Ecosystems
WordPress
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.