CVE-2026-25368: WordPress Calculated Fields Form plugin <= 5.4.4.1 - Broken Access Control vulnerability
Published Feb 19, 2026
·Updated
Missing Authorization vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Calculated Fields Form: from n/a through <= 5.4.4.1.
Affected Software
2 affected components
CodePeople Calculated Fields Form<=5.4.4.1
wordpress/calculated-fields-form<=5.4.4.1
Event History
Feb 19, 2026
CVE Published
via MITRE·08:26 AM
Data Sourced
via MITRE·08:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25368?
CVE-2026-25368 is classified as a broken access control vulnerability.
2
How do I fix CVE-2026-25368?
To fix CVE-2026-25368, update the Calculated Fields Form plugin to version 5.4.4.2 or later.
3
What systems are affected by CVE-2026-25368?
CVE-2026-25368 affects versions of the Calculated Fields Form plugin up to and including 5.4.4.1.
4
What types of attacks can exploit CVE-2026-25368?
CVE-2026-25368 can be exploited to allow unauthorized access to functionality or data that should be restricted.
5
What is the cause of CVE-2026-25368?
CVE-2026-25368 is caused by incorrectly configured access control security levels in the plugin's code.