CVE-2026-32446: WordPress Contact Form by WPForms plugin <= 1.9.9.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through <= 1.9.9.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32446?
CVE-2026-32446 is classified as a Broken Access Control vulnerability in the WPForms Contact Form plugin.
How do I fix CVE-2026-32446?
To address CVE-2026-32446, update the WPForms Contact Form plugin to the latest version beyond 1.9.9.3.
What are the potential impacts of CVE-2026-32446?
The potential impacts of CVE-2026-32446 include unauthorized access to restricted functionalities within the WPForms Contact Form plugin.
Who is affected by CVE-2026-32446?
Users of the WPForms Contact Form plugin version 1.9.9.3 or earlier are affected by CVE-2026-32446.
Is there a known exploit for CVE-2026-32446?
At this time, specific exploits for CVE-2026-32446 have not been publicly disclosed.