The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-11 06:17
Updated : 2026-03-11 14:16
NVD link : CVE-2026-1753
Mitre link : CVE-2026-1753
CVE.ORG link : CVE-2026-1753
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
