What the vulnerability does
01Description
Missing Authorization vulnerability in Codexpert, Inc CF7 Submissions cf7-submissions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 Submissions: from n/a through <= 0.26.
Explanation of Vulnerability in Simple Terms
02Summary
CF7 Submissions versions 0.26 and earlier lack proper authorization checks, allowing authenticated users with low privileges to modify submission data they should not have access to. The vulnerability requires a valid user account but no special interaction. Site administrators should update to a version newer than 0.26 to prevent unauthorized data tampering.
What an attacker can do
03Attacker Capabilities
Modify form submissions or submission data belonging to other users or restricted areas.
Potential impact on your site
04Site Impact
Authenticated users can alter form submissions, potentially corrupting data integrity or accessing restricted submission records.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site; no user interaction required.
Key dates
06Disclosure timeline
September 22, 2025
CVE published
May 12, 2026
Record updated