plugin

Form Notify Vulnerabilities

1 known security issue reported for the Form Notify WordPress plugin. Most recent disclosed May 14, 2026.

1 critical

Running Form Notify on your site? Check whether your installed version is affected.

Scan your site free

Receive Notifications After Form Submitting – Form Notify for Any Forms <= 1.1.10 - Unauthenticated Authentication Bypass via LINE OAuth Callback

critical

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which WordPress account to authenticate after a LINE OAuth login. When LINE doesn't provide an email address (which is common),...

CVSS:
9.8
Affected:
up to 1.1.10
Fixed in:
1.1.11
Disclosed:
May 14, 2026

CVE-2026-5229 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database