CVE-2026-9178 | hancock11 WP Forms Connector Plugin up to 1.8 on WordPress Password Hash /v3/user/list userDetail authorization

SecurityVulns

A vulnerability was found in hancock11 WP Forms Connector Plugin up to 1.8 on WordPress. It has been rated as problematic. Affected is the function userDetail of the file /v3/user/list of the component Password Hash Handler. The manipulation leads to missing authorization.

This vulnerability is listed as CVE-2026-9178. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.VulDB Recent EntriesRead More