The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stored configuration in the response to its public submission handler, allowing unauthenticated users to disclose notification recipient addresses, confirmation redirect targets and integration settings, including those of unpublished forms.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-02 06:17
Updated : 2026-09-03 17:50
NVD link : CVE-2026-78151
Mitre link : CVE-2026-78151
CVE.ORG link : CVE-2026-78151
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
