← WordPress Vulnerabilities
WordPress security by component

formlayer

formlayer (formlayer) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 5.3.

Plugin slug: formlayer

CVE-2026-78151: FormLayer exposes complete form configurations without authentication

FormLayer before 1.0.9 returns a form's complete stored configuration through its public submission handler without authorization. An unauthenticated visitor can disclose notification recipients, confirmation redirects, integration settings, and configurations belonging to unpublished forms.

PublishedSep 02, 2026
Known safe version1.0.9
Published vulnerabilities for formlayer
Safe version
Sep 02, 2026 CVE-2026-78151
FormLayer exposes complete form configurations without authentication
FormLayer before 1.0.9 returns a form's complete stored configuration through its public submission handler without authorization. An unauthenticated visitor can disclose notification recipients, confirmation redirects, integration settings, and configurations belonging to unpublished forms.
1.0.9
CVE5.3
NVDPending
Jul 05, 2026 CVE-2026-59519
FormLayer: A security weakness
FormLayer is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.0.6.
1.0.7
CVE5.3
NVDPending