CVE-2026-78151

The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stored configuration in the response to its public submission handler, allowing unauthenticated users to disclose notification recipient addresses, confirmation redirect targets and integration settings, including those of unpublished forms.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 06:17

Updated : 2026-09-03 17:50


NVD link : CVE-2026-78151

Mitre link : CVE-2026-78151

CVE.ORG link : CVE-2026-78151


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor