WP Forms Connector <= 1.8 - Missing Authorization to Unauthenticated Information Exposure via 'user/list' REST Endpoint
high
The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/list/<id> (callback userDetail()) with permission_callback set to '__return_true', and the function's home-grown authentication only verifies that t...
- CVSS:
- 7.5
- Affected:
- up to 1.8
- Fix:
- No patched version reported
- Disclosed:
- Jun 23, 2026
CVE-2026-9178 on NVD →
WP Forms Connector <= 1.8 - Unauthenticated SQL Injection via 'order' Parameter
high
The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and including 1.8. This is due to insufficient escaping on the user-supplied 'order' parameter (read directly from $_GET['order'] into $shorting) and the l...
- CVSS:
- 7.5
- Affected:
- up to 1.8
- Fix:
- No patched version reported
- Disclosed:
- Jun 23, 2026
CVE-2026-9179 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database