Vulnerability Description
The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the structure of any form — adding, removing, or altering fields — by writing attacker-controlled data to the plugin's FORMS database table. The 'ajax-nonce' nonce used by this handler is injected into the public frontend via wp_localize_script(), so any authenticated user who visits a page containing a form shortcode can obtain it without any elevated access.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration-builder/ta
- https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration-builder/ta
- https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration-builder/ta
- https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration-builder/ta
- https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration-builder/ta
- https://plugins.trac.wordpress.org/browser/vedrixa-forms-registration-builder/ta
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1b3b8a6c-1c84-4abe-ad4
FAQ
What is CVE-2026-8692?
CVE-2026-8692 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.1. This is due t...
How severe is CVE-2026-8692?
CVE-2026-8692 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-8692?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.