The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).
Metrics
Affected Vendors & Products
References
History
Thu, 12 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gutena Forms
Gutena Forms gutena Forms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Gutena Forms
Gutena Forms gutena Forms Wordpress Wordpress wordpress |
Wed, 11 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| Metrics |
cvssV3_1
|
Wed, 11 Mar 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register). | |
| Title | Gutena Forms < 1.6.1 - Contributor+ Arbitrary Limited Options Update | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-03-11T13:46:58.114Z
Reserved: 2026-02-02T09:47:03.130Z
Link: CVE-2026-1753
Updated: 2026-03-11T13:43:32.832Z
Status : Awaiting Analysis
Published: 2026-03-11T06:17:13.273
Modified: 2026-03-11T14:16:17.287
Link: CVE-2026-1753
No data.