The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 11 Mar 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register). | |
| Title | Gutena Forms < 1.6.1 - Contributor+ Arbitrary Limited Options Update | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-03-11T06:00:03.165Z
Reserved: 2026-02-02T09:47:03.130Z
Link: CVE-2026-1753
No data.
Status : Received
Published: 2026-03-11T06:17:13.273
Modified: 2026-03-11T06:17:13.273
Link: CVE-2026-1753
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.