cleantalk
Vulnerabilities and Security Researches

Gutena Forms – Contact Forms Block, CVE-2026-1753

CVE, Research URL

CVE-2026-1753

Published on
Mar 11, 2026
Research Description
The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).
Affected versions
max 1.6.1.
Status
vulnerable