plugin

Gutena Forms Vulnerabilities

5 known security issues reported for the Gutena Forms WordPress plugin. Most recent disclosed Aug 5, 2026.

5 medium

Running Gutena Forms on your site? Check whether your installed version is affected.

Scan your site free

Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization

medium

The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.0. This makes it possible for unauthenticated attackers to perform an una...

CVSS:
5.3
Affected:
up to 1.9.0
Fixed in:
2.0.0
Disclosed:
Aug 5, 2026

CVE-2026-66425 on NVD →

Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification/Trash via process_bulk_action()

medium

The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.9.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possib...

CVSS:
5.3
Affected:
up to 1.9.0
Fixed in:
2.0.0
Disclosed:
Jul 31, 2026

CVE-2026-11995 on NVD →

Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder - Contributor+ Arbitrary Limited Options Update vulnerability

medium

Contributor+ Arbitrary Limited Options Update vulnerability

CVSS:
6.8
Affected:
up to 1.6.1
Fixed in:
1.6.1
Disclosed:
Mar 12, 2026

Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder < 1.6.1 - Missing Authorization to Authenticated (Contributor+) Settings Update

medium

The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 1.6.1 (exclusive). This makes it possible for authenticated attackers, with Contributor-level...

CVSS:
4.3
Affected:
up to 1.6.1
Fixed in:
1.6.1
Disclosed:
Mar 12, 2026

CVE-2026-1753 on NVD →

Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 - Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema()

medium

The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization within the save_gutena_forms_schema() function in all versions up to, and including, 1.6.0. This makes it possible for a...

CVSS:
6.5
Affected:
up to 1.6.0
Fixed in:
1.6.1
Disclosed:
Mar 3, 2026

CVE-2026-1674 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database