WordPress security by component
Advanced Forms
Advanced Forms (advanced-forms) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 13, 2026; the highest published CVSS base score is 8.8.
Plugin slug:
advanced-formsLatest vulnerability
CVE-2026-57378: Advanced Forms: A security weakness
Advanced Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.9.3.7.
| Safe version |
|
||
|---|---|---|---|
| Jul 13, 2026 |
CVE-2026-57378
Advanced Forms: A security weakness
Advanced Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.9.3.7.
|
1.9.3.8 |
CVE7.5
NVDPending
|
| Nov 23, 2021 |
CVE-2021-24892
Advanced Forms: Broken access control
Advanced Forms is affected by broken access control. Exposure depends on how the affected operation is made reachable by the site. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
|
See mitigation notes |
CVEPending
NVD8.8
|