Get real-time updates on Telegram
Verified
CVE-2026-105260: Database Addon For WPForms ( wpforms entries ) 0 to before 1.1.1
Affected technology
Database Addon For WPForms ( wpforms entries ) · 0 to before 1.1.1
Vendor not specified by the source
Description’s affected range: before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 08:50:52.119177+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 08:49:39.219831+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-105260.html