CVE-2026-104797 | nasirahmed Advanced Form Integration Plugin up to 2.9.0 on WordPress Update Profile Field adfoin_ultimatememberac_send_data user_pass improper authentication

SecurityVulns

A vulnerability, which was classified as critical, has been found in nasirahmed Advanced Form Integration Plugin up to 2.9.0 on WordPress. This affects the function adfoin_ultimatememberac_send_data of the component Update Profile Field. The manipulation of the argument user_pass leads to improper authentication.

This vulnerability is traded as CVE-2026-104797. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More