Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Wed, 02 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 02 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-284 |
Wed, 02 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stored configuration in the response to its public submission handler, allowing unauthenticated users to disclose notification recipient addresses, confirmation redirect targets and integration settings, including those of unpublished forms. | |
| Title | FormLayer < 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Submission Response | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-02T10:45:56.493Z
Reserved: 2026-08-23T06:58:20.794Z
Link: CVE-2026-78151
Updated: 2026-09-02T10:11:53.917Z
Status : Received
Published: 2026-09-02T06:17:18.160
Modified: 2026-09-02T11:17:21.747
Link: CVE-2026-78151
No data.
OpenCVE Enrichment
Updated: 2026-09-02T15:45:04Z
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor