The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-02 15:17
Updated : 2026-09-03 17:50
NVD link : CVE-2026-2688
Mitre link : CVE-2026-2688
CVE.ORG link : CVE-2026-2688
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
