Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Formsplayer
Formsplayer formsplayer Wordpress Wordpress wordpress |
|
| Vendors & Products |
Formsplayer
Formsplayer formsplayer Wordpress Wordpress wordpress |
Wed, 02 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Wed, 02 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 02 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-284 |
Wed, 02 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stored configuration in the response to its public submission handler, allowing unauthenticated users to disclose notification recipient addresses, confirmation redirect targets and integration settings, including those of unpublished forms. | |
| Title | FormLayer < 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Submission Response | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-02T10:45:56.493Z
Reserved: 2026-08-23T06:58:20.794Z
Link: CVE-2026-78151
Updated: 2026-09-02T10:11:53.917Z
Status : Deferred
Published: 2026-09-02T06:17:18.160
Modified: 2026-09-03T17:50:37.690
Link: CVE-2026-78151
No data.
OpenCVE Enrichment
Updated: 2026-09-03T16:00:07Z