CVE-2026-28571: WordPress FormyChat plugin <= 2.15.7 - Broken Access Control vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
Affected Software
1 affected component
WordPress FormyChat plugin<=2.15.7
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Sites using FormyChat version 2.15.7 or earlier are in scope. The issue is remotely exploitable without authentication, user interaction, or prior privileges.
2
What does an attacker need to exploit this issue?
An unauthenticated remote attacker can exploit the broken access control with low attack complexity. The listed impact is high confidentiality impact, with no integrity or availability impact indicated.