Home

Description

The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).

PUBLISHED Reserved 2026-02-02 | Published 2026-03-11 | Updated 2026-03-11 | Assigner WPScan

Problem types

CWE-639 Authorization Bypass Through User-Controlled Key

Product status

Default status
unaffected

Any version before 1.6.1
affected

Credits

yiğit ibrahim sağlam finder

WPScan coordinator

References

wpscan.com/...rability/c42dbab9-b729-4748-88e5-0bd2f6d66e3d/ exploit vdb-entry technical-description

cve.org (CVE-2026-1753)

nvd.nist.gov (CVE-2026-1753)

Download JSON