Sceawere

Vulnerability Detail

CVE-2026-94499UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FormGent Subscriber Broken Access Control

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
wpWax
Product
FormGent
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Broken Access Control in FormGent <= 1.12.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:27.007Z",
  "pubdate": "2026-09-30T13:17:27.007Z",
  "executiveSummary": "A broken access control vulnerability exists in the FormGent plugin for WordPress in versions 1.12.2 and earlier. The flaw permits users with the 'Subscriber' role to perform unauthorized actions due to improper capability checks during form processing or configuration requests.\nThe vulnerability type is categorized under broken access control, specifically reflecting an Insecure Direct Object Reference (IDOR) or missing functional level access control. This vulnerability poses a significant risk to the integrity and confidentiality of the plugin's data.\nImpact includes the potential for unauthorized modification of form settings, access to sensitive submission data, or the ability to manipulate form configurations that should be restricted to administrative roles.\nThe attack is remotely exploitable and does not require elevated privileges beyond a standard subscriber account. Attackers can leverage this to gain unauthorized administrative-level control over the plugin’s functionality without requiring elevated server access.\nSuccessful exploitation allows an authenticated attacker to bypass intended security constraints, leading to a compromise of the application's form management ecosystem.",
  "technicalDetails": "The root cause of the vulnerability lies in the insufficient enforcement of administrative capability checks within the FormGent plugin's backend handler functions. Specifically, functions responsible for modifying plugin settings or processing administrative form requests fail to verify the user's role before executing the requested operation.\nIn WordPress, sensitive administrative actions must be protected by the current_user_can() function, checking against capabilities like 'manage_options' or specific plugin-defined capabilities. The FormGent plugin fails to perform this validation, allowing any authenticated user—including those with the lowest subscriber-level permissions—to trigger these restricted backend functions.\nThe attack flow begins with the authenticated subscriber identifying the target AJAX or REST API endpoint responsible for configuration changes or data retrieval. By crafting a request that mirrors legitimate administrative traffic, the attacker can submit parameters to the vulnerable controller. Because the backend does not validate the security nonce or the session's privilege level, the application treats the request as a legitimate command from an administrator.\nExploitation involves sending a POST request to the vulnerable endpoint with the appropriate payload. If the application logic relies on user-supplied IDs to fetch or update records, the attacker may also iterate through IDs to view or manipulate data belonging to other users or the system as a whole, typical of an IDOR attack path.\nThe vulnerable component resides within the plugin’s request handling logic where authentication hooks are either missing, improperly implemented, or bypassed. The exposure is network-based, as the plugin is accessible via the standard WordPress front-end or back-end request handling mechanisms. There are no specific complex requirements for exploitation other than an active, authenticated subscriber account on the target WordPress installation.\nPost-exploitation impact may include unauthorized data exfiltration, the modification of form behavior to redirect submissions to attacker-controlled endpoints, or the injection of malicious content into form fields that are rendered to administrators, potentially leading to further vulnerabilities such as Stored Cross-Site Scripting (XSS)."
}
CVE-2026-94499: FormGent Subscriber Broken Access Control (HIGH Severity, CVSS: 7.1) | Sceawere