CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105260

MEDIUMCVSS 4.3NVD feed

Published 8 October 2026 · tracked since 8 October 2026

Description

The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attackers to delete arbitrary stored form entries by tricking a logged-in administrator into loading a craf

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-105260 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105260

MEDIUMCVSS 4.3NVD feed

Published 8 October 2026 · tracked since 8 October 2026

Description

The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attackers to delete arbitrary stored form entries by tricking a logged-in administrator into loading a craf

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]