{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T18:19:44.187","vulnerabilities":[{"cve":{"id":"CVE-2026-1674","sourceIdentifier":"security@wordfence.com","published":"2026-03-04T12:16:02.733","lastModified":"2026-06-17T10:16:17.847","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization within the save_gutena_forms_schema() function in all versions up to, and including, 1.6.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to update option values to a structured array value on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny service to legitimate users or be used to set some values, that would, for example enable site user registration when it is explicitly disabled."},{"lang":"es","value":"El plugin Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, y Custom Form Builder para WordPress es vulnerable a la modificación no autorizada de datos debido a la falta de autorización dentro de la función save_gutena_forms_schema() en todas las versiones hasta la 1.6.0, inclusive. Esto hace posible que atacantes autenticados, con acceso de nivel Colaborador y superior, actualicen los valores de las opciones a un valor de array estructurado en el sitio de WordPress. Esto puede ser aprovechado para actualizar una opción que crearía un error en el sitio y denegar el servicio a usuarios legítimos o ser usado para establecer algunos valores que, por ejemplo, habilitarían el registro de usuarios del sitio cuando está explícitamente deshabilitado."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"saadiqbal","product":"Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.6.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-04T15:00:49.809121Z","id":"CVE-2026-1674","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/changeset/3463148/gutena-forms","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4bc10693-6d7c-4293-8848-02181ceb0d25?source=cve","source":"security@wordfence.com"}]}}]}