What is CVE-2026-16587?
An authorization bypass vulnerability exists in the "Advanced Form Integration - Connect Forms to 200+ Apps" plugin for WordPress, allowing authenticated users to perform unauthorized actions. This affects all plugin versions up to and including 2.6.0, and users should update to the latest version immediately.
Azərbaycanca: WordPress üçün "Advanced Form Integration - Connect Forms to 200+ Apps" pluginində autentifikasiyalı istifadəçilərə icazəsiz əməliyyatlar aparmağa imkan verən authorization bypass zəifliyi aşkarlanıb. Pluginin 2.6.0 və daha əvvəlki versiyaları təsirlənir. Pluginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What is the CVE-2026-16587 vulnerability in the 'Advanced Form Integration' plugin for WordPress?
This vulnerability is an authorization bypass issue that allows authenticated users to perform unauthorized actions.
Which versions of the 'Advanced Form Integration' plugin are affected by CVE-2026-16587?
All plugin versions up to and including 2.6.0 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.