CVE-2026-104797 - Advanced Form Integration <= 2.9.0 - Unauthenticated Unverified Password Change to Authentication Bypass / Privilege Escalation via Contact Form 7 Submission to Ultimate Member Update Profile Field Action
CVE ID :CVE-2026-104797 Published : Oct. 10, 2026, 4:18 a.m. | 1 hour, 11 minutes ago Description :The Advanced Form Integration — Connect Forms to 300+ Apps plugin for WordPress is vulnerable to Authentication Bypass via Unverified Password Change in all versions up to, and including, 2.9.0...