Sceawere
Vulnerability Detail
CVE-2026-105260UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CSRF Arbitrary Entry Deletion Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Database Addon For WPForms ( wpforms entries )
- Attack Type
- CWE-352 Cross-Site Request Forgery (CSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attackers to delete arbitrary stored form entries by tricking a logged-in administrator into loading a crafted page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-08T06:16:41.130Z",
"pubdate": "2026-10-08T06:16:41.130Z",
"executiveSummary": "The Database Addon For WPForms WordPress plugin, specifically regarding the 'wpforms entries' functionality, contains a critical Cross-Site Request Forgery (CSRF) vulnerability in versions prior to 1.1.1.\nThe flaw stems from improper validation of anti-CSRF tokens and a complete lack of server-side capability checks during the form entry deletion process.\nThis vulnerability allows an unauthenticated remote attacker to craft a malicious request—typically hosted on a separate web page—that forces a logged-in administrator to perform unauthorized actions.\nWhen a legitimate administrator interacts with the attacker's crafted page, the browser automatically submits the unauthorized request to the WordPress site, resulting in the permanent deletion of arbitrary stored form entries.\nThe impact is significant, as it leads to the unauthorized loss of sensitive user-submitted data stored within the plugin database.\nExploitation requires the attacker to successfully perform social engineering to induce a logged-in administrator to access the malicious payload. No direct network access to the target WordPress database is required by the attacker, as the exploit is executed through the victim's session.",
"technicalDetails": "The vulnerability resides in the administrative interface handling the deletion of 'wpforms entries'. The root cause of this security flaw is twofold: the absence of a mandatory anti-CSRF nonce verification when the field is omitted from the request, and the failure to implement essential capability checks (e.g., current_user_can()) before executing the deletion logic.\nIn WordPress development, standard security practices require that sensitive operations—such as deleting database records—be protected by a nonce, which is a unique token used to verify that the request originated from a legitimate administrative session. In the vulnerable versions of this plugin, the backend code fails to validate or even demand this token if it is missing from the request structure. Furthermore, the handler lacks the necessary permission checks that would verify if the requester possesses the 'manage_options' or equivalent capability, effectively allowing any request sent to the handler to be processed as if it were legitimate.\nThe attack flow proceeds as follows: An attacker identifies the specific URL or request structure used by the plugin to delete entries. They construct an HTML document containing a hidden form, a scripted XMLHttpRequest, or a simple `<img>` tag that targets the vulnerable endpoint with the appropriate entry ID parameters. This page is then hosted on a third-party domain or injected into a separate vulnerable site. The attacker then lures a logged-in WordPress administrator into visiting the malicious URL. Because the administrator’s browser maintains an active session with the WordPress site, the browser includes the necessary session cookies in the forged request. The server receives the request, finds no nonce or capability restrictions to block the action, and proceeds to delete the specified entry from the database. The impact is essentially a blind, non-destructive deletion of entries, which can be leveraged to disrupt operations, hide information, or erase proof of previous form submissions. The scope is limited to the functionality of the WPForms Database Addon but remains a high-severity issue due to the irreversible nature of the data deletion."
}