CVE-2026-2688

The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 15:17

Updated : 2026-09-03 17:50


NVD link : CVE-2026-2688

Mitre link : CVE-2026-2688

CVE.ORG link : CVE-2026-2688


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization