CVE WATCH / VULNERABILITY DETAIL

CVE-2026-104797

HIGHCVSS 8.1NVD feed

Published 10 October 2026 · tracked since 10 October 2026

Description

The Advanced Form Integration — Connect Forms to 300+ Apps plugin for WordPress is vulnerable to Authentication Bypass via Unverified Password Change in all versions up to, and including, 2.9.0 The `adfoin_ultimatememberac_send_data` function, which powers the Ultimate Member "Update Profile Field"

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-104797 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-104797

HIGHCVSS 8.1NVD feed

Published 10 October 2026 · tracked since 10 October 2026

Description

The Advanced Form Integration — Connect Forms to 300+ Apps plugin for WordPress is vulnerable to Authentication Bypass via Unverified Password Change in all versions up to, and including, 2.9.0 The `adfoin_ultimatememberac_send_data` function, which powers the Ultimate Member "Update Profile Field"

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]